Skip to main content

CVE detail

CVE-2024-33807

A SQL injection vulnerability in /model/get_teacher_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the grade parameter.

CVSS 5.4 · Medium