Security Advisory

CVE-2024-27709

9.8
CRITICAL

Vulnerability Description

SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the searchby parameter of the allstudents.php component and the id parameter of the requestmanager.php component.
Published Date July 5, 2024
Official Source NIST NVD Advisory