A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /edit-staff/ of the component Staff Handler. The manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
History

Tue, 04 Feb 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Campcodes
Campcodes school Management Software
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:campcodes:school_management_software:1.0:*:*:*:*:*:*:*
Vendors & Products Campcodes
Campcodes school Management Software

Thu, 30 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jan 2025 01:45:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as critical has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /edit-staff/ of the component Staff Handler. The manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Title CampCodes School Management Software Staff edit-staff improper authorization
Weaknesses CWE-266
CWE-285
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-01-30T15:12:09.639Z

Reserved: 2025-01-29T17:12:25.501Z

Link: CVE-2025-0849

cve-icon Vulnrichment

Updated: 2025-01-30T15:11:39.802Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-30T02:15:25.783

Modified: 2025-02-04T16:27:36.197

Link: CVE-2025-0849

cve-icon Redhat

No data.