Security Advisory
CVE-2024-27709
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the searchby parameter of the allstudents.php component and the id parameter of the requestmanager.php component.