ZeroHour

CVE-2022-1287

CVSS 3.1
9.8 critical
EPSS
<1%p52
Published
()
Modified
Description

A vulnerability classified as critical was found in School Club Application System 1.0. This vulnerability affects a request to the file /scas/classes/Users.php?f=save_user. The manipulation with a POST request leads to privilege escalation. The attack can be initiated remotely and does not require authentication. The exploit has been disclosed to the public and may be used.

Vendors
school club application system project
Products
school club application system
Weakness
CWE-99, CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.