First published: Sun Jul 28 2024(Updated: )
A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been classified as critical. Affected is an unknown function of the file /receipt.php. The manipulation of the argument ef_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272580.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oretnom23 School Fees Payment System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7166 is classified as a critical vulnerability.
CVE-2024-7166 affects the SourceCodester School Fees Payment System version 1.0, specifically an unknown function in the file /receipt.php.
CVE-2024-7166 is a SQL injection vulnerability that allows remote attacks.
To fix CVE-2024-7166, it is essential to sanitize user inputs and implement prepared statements in the affected areas of the application.
CVE-2024-7166 can be exploited by manipulating the ef_id argument in a request to the /receipt.php file.