Aller au contenu

Fiche vulnérabilité

CVE-2024-33974 : faille critique janobe school attendence monitoring… (CVSS 9.8)

Description

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Users in '/report/printlogs.php' parameter.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
6 août 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • janobe school attendence monitoring system
  • janobe school event management system

Références

Rechercher une autre vulnérabilité dans la base CVE