VYPR
Unrated severityNVD Advisory· Published Feb 9, 2024· Updated Jun 17, 2025

CVE-2024-25309

CVE-2024-25309

Description

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Simple School Managment System 1.0 has an SQL injection vulnerability in the 'pass' parameter at teacher_login.php, allowing an attacker to extract or modify database data.

Vulnerability

The Simple School Managment System version 1.0 from Code-projects contains a SQL injection vulnerability in the pass parameter at the teacher login page School/teacher_login.php. The application fails to sanitize user-supplied input before using it in SQL queries, enabling an attacker to inject arbitrary SQL commands [1].

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP POST request to the login endpoint, manipulating the pass parameter with SQL injection payloads. The attacker requires network access to the web application and no authentication, as the vulnerable endpoint is a login form. The exploit proof of concept uses sqlmap against a captured request to automate the injection and extract data from the database [1].

Impact

Successful exploitation allows an attacker to bypass authentication, retrieve sensitive information from the database (such as user credentials), modify database content, or potentially gain further access to the underlying system depending on database permissions. The compromised data could include personal information of students, teachers, and administrators [1].

Mitigation

As of the publication date (2024-02-09), no patched version or vendor-supplied fix is available. The vendor homepage and software link are provided, but no update has been released. The recommended mitigation is to apply input validation and parameterized queries to the login functionality, particularly the pass parameter [1]. Users should monitor the vendor's site for future updates.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.