CVE-2024-33974 is a critical SQL injection vulnerability impacting version 1.0 of the PayPal, Credit Card, and Debit Card Payment module within janobe's school_attendence_monitoring_system and school_event_management_system. With a CVSS score of 9.8, this vulnerability allows unauthenticated attackers to remotely execute specially crafted queries via the '/report/printlogs.php' parameter, leading to full compromise of confidentiality, integrity, and availability of the affected systems. While there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable. Despite the lack of media coverage, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:janobe:school_attendence_monitoring_system:1.0:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:janobe:school_event_management_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.