CVE-2024-28094: Schoolbox

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the authenticated attackers to read, modify, and delete database records.

Affected products

  • Schoolbox Schoolbox: before 23.1.3 (fixed in 23.1.3)

Published 2024-03-07. Last modified 2026-06-17.