CVE-2024-50830

CVSS 3.1 Score 3.5 of 10 (low)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 89

Summary

CVE-2024-50830: A SQL injection vulnerability has been identified in the /admin/calendar_of_events.php file of the kashipara E-learning Management System Project 1.0. This vulnerability can be exploited through maliciously crafted input in the date_start, date_end, and title parameters, potentially allowing unauthorized access or data modification. SQL injection attacks can lead to significant security risks, including sensitive data exposure or system compromise. It is recommended that users of this E-learning Management System upgrade to a patch or newer version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share