CampCodes School Management Software Attachment Resource Injection Vulnerability

Vulnerability

A resource injection vulnerability has been identified in CampCodes School Management Software version 1.0, specifically within the Attachment Handler component. This vulnerability arises from improper management of resource identifiers, allowing for insecure direct object reference (IDOR) exploitation. The issue can be exploited remotely, although the attack's complexity is considered high.

Impact

Exploitation of this vulnerability allows for insecure direct object reference, enabling unauthorized access to resources by manipulating sequential and guessable identifiers. This could lead to unauthorized downloading of homework assignments from other students.

Reproduction

To reproduce this vulnerability, access the application and navigate to the homework upload section. Each student's homework is assigned a unique, sequential ID that can be easily guessed. By manipulating these IDs, it is possible to download homework from other students in different classes.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
7.2
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.