Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, examname, classes_id, es_voucherid, es_class, etc. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the database.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-44415 Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, examname, classes_id, es_voucherid, es_class, etc. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the database.
Fixes

Solution

There is no reported solution at this time.


Workaround

No workaround given by the vendor.

History

Thu, 23 Oct 2025 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Arox
Arox school Erp Pro\+responsive
CPEs cpe:2.3:a:arox:school_erp_pro\+responsive:1.0:*:*:*:*:*:*:*
Vendors & Products Arox
Arox school Erp Pro\+responsive

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T20:55:09.885Z

Reserved: 2024-05-13T07:19:21.405Z

Link: CVE-2024-4824

cve-icon Vulnrichment

Updated: 2024-08-01T20:55:09.885Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-14T15:45:15.703

Modified: 2025-10-23T12:27:05.607

Link: CVE-2024-4824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.