CVE-2024-4526
Last modified
CVE-2024-4526 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /view/student_payment_details3.php. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /view/student_payment_details3.php. The manipulation of the argument month leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263129 was assigned to this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Campcodes | Complete Web-Based School Management System | 1.0 |
References
- https://vuldb.com/?ctiid.263129Permissions Required, VDB Entry
- https://vuldb.com/?id.263129Permissions Required, VDB Entry
- https://vuldb.com/?submit.329772Third Party Advisory, VDB Entry
- https://vuldb.com/?ctiid.263129Permissions Required, VDB Entry
- https://vuldb.com/?id.263129Permissions Required, VDB Entry
- https://vuldb.com/?submit.329772Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-4526?
How severe is CVE-2024-4526?
How do I fix CVE-2024-4526?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45253Avigilon – CWE-22: Improper Limitation of a Pathname to a Re…7.5
- CVE-2024-45254VaeMendis - CWE-79: Improper Neutralization of Input During …7.5
- CVE-2024-45256An arbitrary file write issue in the exfiltration endpoint i…9.8
- CVE-2024-45257A Command Injection issue in the payload build page in BYOB …7.3
- CVE-2024-45258The req package before 3.43.4 for Go may send an unintended …9.8
- CVE-2024-45259An issue was discovered on certain GL-iNet devices, includin…6.5
- CVE-2024-45260An issue was discovered on certain GL-iNet devices, includin…8
- CVE-2024-45261An issue was discovered on certain GL-iNet devices, includin…8
- CVE-2024-45262An issue was discovered on certain GL-iNet devices, includin…8.8
- CVE-2024-45263An issue was discovered on certain GL-iNet devices, includin…8.8
- CVE-2024-45264A cross-site request forgery (CSRF) vulnerability in the adm…8.8
- CVE-2024-45265A SQL injection vulnerability in the poll component in SkySy…9.8
Are you affected by CVE-2024-4526?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
