A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1. Affected by this issue is some unknown functionality of the file login.php of the component Login Page. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269480.
History

Thu, 19 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Lahirudanushka
Lahirudanushka school Management System
CPEs cpe:2.3:a:lahirudanushka:school_management_system:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:lahirudanushka:school_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Lahirudanushka
Lahirudanushka school Management System

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-06-23T09:31:04.178Z

Updated: 2024-08-01T21:33:05.341Z

Reserved: 2024-06-22T15:43:36.918Z

Link: CVE-2024-6268

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:05.341Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-23T10:15:09.753

Modified: 2024-09-19T17:06:24.663

Link: CVE-2024-6268

cve-icon Redhat

No data.