CVE-2024-28094
Blind SQL Injection in Chat functionality in Schoolbox
Chat functionality in Schoolbox application before
version 23.1.3 is vulnerable to blind SQL Injection enabling the
authenticated attackers to read, modify, and delete database records.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Schoolbox Pty Ltd · SchoolboxWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →