CVE-2023-51801

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 29, 2024
Updated: Dec 16, 2024
CWE ID 94

Summary

CVE-2023-51801 is a newly disclosed SQL Injection vulnerability affecting the Simple Student Attendance System version 1.0. An attacker can exploit this flaw by sending crafted inputs to the id parameter in the student_form.php and class_form.php pages. Successful exploitation allows the attacker to execute arbitrary code remotely. This vulnerability poses a serious risk and requires immediate attention from system administrators to apply the necessary patches or workarounds.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share