Fiche vulnérabilité
CVE-2024-33974 : faille critique janobe school attendence monitoring… (CVSS 9.8)
Description
SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Users in '/report/printlogs.php' parameter.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 6 août 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- janobe school attendence monitoring system
- janobe school event management system