First published: Wed Aug 07 2024(Updated: )
An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new subject entry.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lopalopa Responsive School Management System | =3.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41248 is classified as a critical vulnerability due to its potential for unauthorized access and manipulation of data.
To fix CVE-2024-41248, ensure proper access controls are implemented in the add_subject.php and add_subject_submit.php files.
The potential impacts of CVE-2024-41248 include unauthorized users being able to add subjects, which could compromise the integrity of the school's data.
Users of Kashipara Responsive School Management System version 3.2.0 are affected by CVE-2024-41248.
At this time, there are no known active exploits for CVE-2024-41248, but its critical nature warrants immediate attention.