CVE-2024-4519
Last modified
CVE-2024-4519 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /view/teacher_salary_details3.php. The manipulation of the argument month leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263123.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Campcodes | Complete Web-Based School Management System | 1.0 |
References
- https://vuldb.com/?ctiid.263123Permissions Required, VDB Entry
- https://vuldb.com/?id.263123Permissions Required, VDB Entry
- https://vuldb.com/?submit.329700Third Party Advisory, VDB Entry
- https://vuldb.com/?ctiid.263123Permissions Required, VDB Entry
- https://vuldb.com/?id.263123Permissions Required, VDB Entry
- https://vuldb.com/?submit.329700Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-4519?
How severe is CVE-2024-4519?
How do I fix CVE-2024-4519?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45184An issue was discovered in Samsung Mobile Processor, Wearabl…6.2
- CVE-2024-45185An issue was discovered in Samsung Mobile Processor, Wearabl…5.1
- CVE-2024-45186FileSender before 2.49 allows server-side template injection…9.8
- CVE-2024-45187Guest users in the Mage AI framework that remain logged in a…8.8
- CVE-2024-45188Mage AI allows remote users with the "Viewer" role to leak a…6.5
- CVE-2024-45189Mage AI allows remote users with the "Viewer" role to leak a…6.5
- CVE-2024-45190Mage AI allows remote users with the "Viewer" role to leak a…6.5
- CVE-2024-45191An issue was discovered in Matrix libolm through 3.2.16. The…5.3
- CVE-2024-45192An issue was discovered in Matrix libolm through 3.2.16. Cac…5.3
- CVE-2024-45193An issue was discovered in Matrix libolm through 3.2.16. The…4.3
- CVE-2024-45194In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability …4.8
- CVE-2024-45195Direct Request ('Forced Browsing') vulnerability in Apache O…7.5
Are you affected by CVE-2024-4519?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
