CVE-2024-7166: SourceCodester School Fees Payment System receipt.php sql injection
A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been classified as critical. Affected is an unknown function of the file /receipt.php. The manipulation of the argument efid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-272580.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7166?
CVE-2024-7166 is classified as a critical vulnerability.
What does CVE-2024-7166 affect?
CVE-2024-7166 affects the SourceCodester School Fees Payment System version 1.0, specifically an unknown function in the file /receipt.php.
What type of vulnerability is CVE-2024-7166?
CVE-2024-7166 is a SQL injection vulnerability that allows remote attacks.
How can I fix CVE-2024-7166?
To fix CVE-2024-7166, it is essential to sanitize user inputs and implement prepared statements in the affected areas of the application.
How is CVE-2024-7166 exploited?
CVE-2024-7166 can be exploited by manipulating the ef_id argument in a request to the /receipt.php file.