CVE-2024-33808
Description
A SQL injection vulnerability in /model/get_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.
In plain language
AI Worth attentionComplete Web-Based School Management System 1.0 has a critical flaw that can let an internet attacker access or alter its database, so affected businesses should restrict access and seek a vendor fix now.
Unauthenticated SQL injection in `/model/get_timetable.php` via the `id` parameter permits arbitrary SQL command execution against Complete Web-Based School Management System 1.0.
What to do now
- Confirm whether you run Complete Web-Based School Management System 1.0 and whether its timetable page is accessible from the internet.
- Until it is fixed, limit access to the system to trusted staff networks or a VPN and block public access to
/model/get_timetable.phpwhere practical. - Ask the software vendor for a supported fixed release; no fixed version has been published in the available information.
- Review database and web-server logs for unusual requests to the timetable page, especially unexpected
idvalues.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2024-33808 and every CVE in our database. Create a free account — no credit card required.
Create Free Account