CVE-2024-50826

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 89

Summary

CVE-2024-50826 refers to a SQL Injection vulnerability discovered in the kashipara E-learning Management System Project 1.0, specifically in the /admin/add_content.php file. This issue arises due to insufficient input validation on the title and content parameters, making it possible for attackers to inject malicious SQL queries and potentially gain unauthorized access to sensitive data or even take control of the system. This flaw poses a serious threat to the confidentiality and integrity of information processed by affected installations. It is crucial for users to apply the necessary patches or updates as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share