VYPR
Unrated severityNVD Advisory· Published Feb 9, 2024· Updated Jun 12, 2025

CVE-2024-25308

CVE-2024-25308

Description

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Simple School Management System 1.0 has a SQL injection vulnerability in the 'name' parameter of teacher_login.php, allowing attackers to compromise the database.

Vulnerability

Simple School Management System version 1.0, a PHP-based web application, contains a SQL injection vulnerability in the name parameter of the teacher_login.php page [1]. The application fails to sanitize user input, allowing an attacker to inject arbitrary SQL commands. The vulnerable code path is reachable by any user who can access the login page without prior authentication [1].

Exploitation

To exploit the vulnerability, an attacker navigates to the teacher login page at /School/teacher_login.php and submits a crafted HTTP POST request with malicious input in the name parameter [1]. The attacker can capture the request using a proxy tool like Burp Suite and then use automated tools such as sqlmap to extract database contents [1]. The attack requires no authentication and can be performed remotely over the network [1].

Impact

Successful exploitation allows an attacker to compromise the underlying database, potentially leading to unauthorized access, data modification, or disclosure of sensitive information such as user credentials and school records [1]. The impact could extend to full database compromise depending on database server permissions [1].

Mitigation

As of the publication date (2024-02-09), no official patch or fixed version has been released by the vendor [1]. Users should consider input validation and parameterized queries as a workaround, or discontinue use of the application if no update is provided [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.