A vulnerability classified as critical was found in School Club Application System 1.0. This vulnerability affects a request to the file /scas/classes/Users.php?f=save_user. The manipulation with a POST request leads to privilege escalation. The attack can be initiated remotely and does not require authentication. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://vuldb.com/?id.196750 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-04-09 13:15
Updated : 2022-04-15 07:46
NVD link : CVE-2022-1287
Mitre link : CVE-2022-1287
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
school_club_application_system_project
- school_club_application_system


