CVE-2024-7164: SourceCodester School Fees Payment System sql injection
A vulnerability has been found in SourceCodester School Fees Payment System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-272578 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7164?
CVE-2024-7164 is classified as a critical vulnerability.
How does CVE-2024-7164 exploit the system?
CVE-2024-7164 exploits the system through SQL injection via the username parameter in the /ajax.php?action=login file.
Which software is affected by CVE-2024-7164?
CVE-2024-7164 affects SourceCodester School Fees Payment System version 1.0.
How can I mitigate CVE-2024-7164?
To mitigate CVE-2024-7164, sanitize input data and use prepared statements to prevent SQL injection.
Is CVE-2024-7164 remotely exploitable?
Yes, CVE-2024-7164 can be exploited remotely.