First published: Mon Jun 24 2024(Updated: )
A vulnerability classified as critical has been found in lahirudanushka School Management System 1.0.0/1.0.1. This affects an unknown part of the file /attendancelist.php of the component Attendance Report Page. The manipulation of the argument aid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269487.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
lahirudanushka School Management System | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6274 is classified as a critical vulnerability.
To fix CVE-2024-6274, it is recommended to update the lahirudanushka School Management System to a version above 1.0.1 if available.
CVE-2024-6274 is a SQL injection vulnerability.
CVE-2024-6274 affects versions 1.0.0 and 1.0.1 of the lahirudanushka School Management System.
CVE-2024-6274 affects the Attendance Report Page component of the software.