CVE-2024-0389
CRITICAL 9.8EPSS 0.8%
A vulnerability, which was classified as critical, was found in SourceCodester Student Attendance System 1.0. Affected is an unknown function of the file attendance_report.php. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250230 is the identifier assigned to this vulnerability. Es wurde eine Schwachstelle in SourceCodester Student Attendance System 1.0 gefunden. Sie wurde als kritisch eingestuft. Es betrifft eine unbekannte Funktion der Datei attendance_report.php. Mit der Manipulation des Arguments class_id mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Der Exploit steht zur öffentlichen Verfügung.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 6.3 MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L - CVSS v2.0
- 5.8 MEDIUM
AV:A/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 0.75% chance of exploitation in the next 30 days, 53th percentile
- Published
- 2024-01-10
- Updated
- 2025-05-09