Back to Database
Status published
High
CVE-2024-28094
Blind SQL Injection in Chat functionality in Schoolbox
Vulnerability Description
Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the authenticated attackers to read, modify, and delete database records.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-28094
Credits & Attribution
No credits recorded in the NVD database.
References
More from Schoolbox Pty Ltd
View All →CVE-2024-28097
Stored Cross-site Scripting in Calendar functionality in Schoolbox
High
7.3
CVE-2024-28096
Stored Cross-site Scripting in Class functionality in Schoolbox
High
7.3
CVE-2024-28095
Stored Cross-site Scripting in News functionality in Schoolbox
High
7.3
CVE-2022-3059
SQL injection in Schoolbox version 21.0.2, by Schoolbox Pty Ltd
High
8.6
CVE-2022-39020
Cross-site scripting in Schoolbox version 21.0.2, by Schoolbox Pty Ltd
High
7.6
Affected Vendor
Schoolbox Pty Ltd
View all reports →Affected Software
Schoolbox
Vulnerable Versions:
0
Timeline
Official Publish:
March 7th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H