CVE-2024-33966: SQL injection in Janobe products
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'xtsearch' in '/admin/modreports/index.php' parameter.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33966?
CVE-2024-33966 is categorized as a high severity SQL injection vulnerability.
How do I fix CVE-2024-33966?
To fix CVE-2024-33966, ensure you update to a version of the affected Janobe products that has patched this vulnerability.
Which software is affected by CVE-2024-33966?
CVE-2024-33966 affects Janobe products including Credit Card, Debit Card Payment, PayPal, School Attendance Monitoring System, and School Event Management System, all on version 1.0.
What type of attack can exploit CVE-2024-33966?
An attacker can exploit CVE-2024-33966 by sending specially crafted SQL queries to the server.
What data could be compromised due to CVE-2024-33966?
Exploitation of CVE-2024-33966 could allow attackers to retrieve sensitive information stored in the database.