First published: Tue Aug 06 2024(Updated: )
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in '/admin/mod_room/index.php' parameter.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Janobe Credit Card | =1.0 | |
Janobe Debit Card Payment | =1.0 | |
Janobe Paypal | =1.0 | |
Janobe School Attendence Monitoring System | =1.0 | |
Janobe School Event Management System | =1.0 |
There is no reported solution at this time.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33963 is classified with a high severity due to its potential impact on sensitive data exposure.
To fix CVE-2024-33963, upgrade to the latest versions of the affected Janobe products.
CVE-2024-33963 affects version 1.0 of Janobe Credit Card, Debit Card Payment, Paypal, School Attendance Monitoring System, and School Event Management System.
CVE-2024-33963 is an SQL injection vulnerability that can lead to unauthorized data retrieval from the database.
Users and administrators of Janobe products that include payment processing features are impacted by CVE-2024-33963.