CVE-2024-4807

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published May 14, 2024
Updated: Jun 4, 2024
CWE ID 89

Summary

CVE-2024-4807 is a critical vulnerability identified in Kashipara College Management System 1.0. This issue arises due to a processing flaw in the file delete_user.php. A manipulated id argument leads to SQL injection, allowing an attacker to execute malicious SQL statements. The exploit can be initiated remotely, and the vulnerability has been publicly disclosed, posing a significant risk. The associated identifier for this issue is VDB-263927.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share