First published: Mon Jun 24 2024(Updated: )
A vulnerability has been found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file subject.php of the component Subject Page. The manipulation of the argument update leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269491.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
lahirudanushka School Management System | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6278 is classified as a critical vulnerability.
CVE-2024-6278 affects the file subject.php of the Subject Page component.
CVE-2024-6278 involves SQL injection due to improper handling of the argument update.
To mitigate CVE-2024-6278, it is recommended to update to the latest version of the lahirudanushka School Management System.
CVE-2024-6278 affects lahirudanushka School Management System versions 1.0.0 and 1.0.1.