{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-6277","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2024-06-23T18:59:37.760Z","datePublished":"2024-06-24T02:00:06.068Z","dateUpdated":"2024-08-01T21:33:05.316Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2024-06-24T02:00:06.068Z"},"title":"lahirudanushka School Management System Student Page student.php sql injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-89","lang":"en","description":"CWE-89 SQL Injection"}]}],"affected":[{"vendor":"lahirudanushka","product":"School Management System","versions":[{"version":"1.0.0","status":"affected"},{"version":"1.0.1","status":"affected"}],"modules":["Student Page"]}],"descriptions":[{"lang":"en","value":"A vulnerability, which was classified as critical, was found in lahirudanushka School Management System 1.0.0/1.0.1. Affected is an unknown function of the file student.php of the component Student Page. The manipulation of the argument update leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-269490 is the identifier assigned to this vulnerability."},{"lang":"de","value":"Es wurde eine Schwachstelle in lahirudanushka School Management System 1.0.0/1.0.1 gefunden. Sie wurde als kritisch eingestuft. Es betrifft eine unbekannte Funktion der Datei student.php der Komponente Student Page. Dank Manipulation des Arguments update mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.1,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":4.7,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":4.7,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":5.8,"vectorString":"AV:N/AC:L/Au:M/C:P/I:P/A:P"}}],"timeline":[{"time":"2024-06-23T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2024-06-23T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2024-06-23T21:04:53.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"louay khammassi (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.269490","name":"VDB-269490 | lahirudanushka School Management System Student Page student.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.269490","name":"VDB-269490 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.362882","name":"Submit #362882 | lahirudanushka School Management System 1.0.1 SQL Injection","tags":["third-party-advisory"]},{"url":"https://powerful-bulb-c36.notion.site/sql-injection-4-a2545288ad9244009ff1097df19ee635","tags":["exploit"]}]},"adp":[{"affected":[{"vendor":"lahirudanushka","product":"school_management_system","cpes":["cpe:2.3:a:lahirudanushka:school_management_system:1.0.1:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1.0.1","status":"affected"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-06-24T14:40:50.421168Z","id":"CVE-2024-6277","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-24T14:46:44.464Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T21:33:05.316Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.269490","name":"VDB-269490 | lahirudanushka School Management System Student Page student.php sql injection","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.269490","name":"VDB-269490 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required","x_transferred"]},{"url":"https://vuldb.com/?submit.362882","name":"Submit #362882 | lahirudanushka School Management System 1.0.1 SQL Injection","tags":["third-party-advisory","x_transferred"]},{"url":"https://powerful-bulb-c36.notion.site/sql-injection-4-a2545288ad9244009ff1097df19ee635","tags":["exploit","x_transferred"]}]}]}}