PT-2023-31441 · Unknown · School Management System

·

CVE-2023-49982

·

Published

2023-12-20

·

Updated

2024-10-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions School Fees Management System version 1.0
Description The issue allows attackers to escalate privileges and perform administrative actions, including adding and deleting user accounts, due to broken access control in the /admin/management/users component.
Recommendations For School Fees Management System version 1.0, consider restricting access to the /admin/management/users component until a fix is available. As a temporary workaround, limit the ability to add and delete user accounts to prevent privilege escalation.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-49982

Affected Products

School Management System