CVE-2024-5232
Last modified
CVE-2024-5232 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as critical. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as critical. This affects an unknown part of the file /view/teacher_salary_details2.php. The manipulation of the argument index leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-265983.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Campcodes | Complete Web-Based School Management System | 1.0 |
References
- https://vuldb.com/?ctiid.265983Permissions Required, VDB Entry
- https://vuldb.com/?id.265983Permissions Required, VDB Entry
- https://vuldb.com/?submit.339808Third Party Advisory, VDB Entry
- https://vuldb.com/?ctiid.265983Permissions Required, VDB Entry
- https://vuldb.com/?id.265983Permissions Required, VDB Entry
- https://vuldb.com/?submit.339808Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-5232?
How severe is CVE-2024-5232?
How do I fix CVE-2024-5232?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-52313An authenticated data.all user is able to manipulate a getDa…5.3
- CVE-2024-52314A data.all admin team member who has access to the customer-…6.9
- CVE-2024-52316Unchecked Error Condition vulnerability in Apache Tomcat. If…9.8
- CVE-2024-52317Incorrect object re-cycling and re-use vulnerability in Apac…6.5
- CVE-2024-52318Incorrect object recycling and reuse vulnerability in Apache…6.1
- CVE-2024-52319In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2024-52320The affected product is vulnerable to a command injection. A…9.8
- CVE-2024-52321Multiple SHARP routers contain an improper authentication vu…5.9
- CVE-2024-52322WebService::Xero 0.11 and earlier for Perl uses the rand() f…5.5
- CVE-2024-52323Zohocorp ManageEngine Analytics Plus versions below 6100 are…8.1
- CVE-2024-52324Ruijie Reyee OS versions 2.206.x up to but not including 2.3…9.8
- CVE-2024-52325ECOVACS robot lawnmowers and vacuums are vulnerable to comma…9.6
Are you affected by CVE-2024-5232?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
