CVE-2024-5235: Campcodes Complete Web-Based School Management System teacher_salary_invoice.php sql injection
A vulnerability classified as critical has been found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/teachersalaryinvoice.php. The manipulation of the argument teacherid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-265986 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5235?
CVE-2024-5235 is classified as a critical vulnerability.
How does CVE-2024-5235 exploit occur?
CVE-2024-5235 exploits occur due to SQL injection via the teacher_id argument in the file /view/teacher_salary_invoice.php.
Who is affected by CVE-2024-5235?
CVE-2024-5235 affects users of Campcodes Complete Web-Based School Management System version 1.0.
How do I fix CVE-2024-5235?
To fix CVE-2024-5235, ensure proper input validation and use prepared statements to prevent SQL injection.
What is the impact of CVE-2024-5235?
The impact of CVE-2024-5235 includes potential unauthorized access to sensitive data through SQL injection.