Security Advisory

CVE-2024-54920

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-12-09 00:00:00
Last updated 2025-03-20 20:25:04
Assigner mitre
State PUBLISHED

Description

A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters.