CVE-2024-5394
itsourcecode Online Student Enrollment System newDept.php sql injection
Description
A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file newDept.php. The manipulation of the argument deptname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-266308.
In plain language
AI Worth attentionOnline Student Enrollment System 1.0 has a flaw that lets a logged-in attacker tamper with school-system data; small businesses using it should address it soon.
Authenticated remote SQL injection in Online Student Enrollment System 1.0 through the `deptname` parameter in `newDept.php`, allowing database queries to be manipulated.
What to do now
- Check whether you run Online Student Enrollment System 1.0 and whether
newDept.phpis present. - Restrict access to the department-management function to only essential, trusted staff while you assess it.
- No fixed version has been published; ask the software supplier for a security update for CVE-2024-5394.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:LConfidentialityI:LIntegrityA:LAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2024-5394 and every CVE in our database. Create a free account — no credit card required.
Create Free Account