CVE-2024-50824

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 89

Summary

CVE-2024-50824: A SQL injection vulnerability has been identified in the kashipara E-learning Management System Project 1.0, specifically in the /admin/class.php file. The issue arises due to insufficient input validation on the class_name parameter, allowing malicious SQL statements to be executed and potentially compromising the system. Attackers can exploit this vulnerability to gain unauthorized access or manipulate data, putting sensitive information at risk. It is recommended that users of this E-learning Management System upgrade to a patched version immediately to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share