Podatność CVE-2023-5008


Publikacja: 2023-12-08   Modyfikacja: 2023-12-14

Opis:
Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.

Typ:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

Affected software
Imsurajghosh -> Student information system 

 Referencje:
https://fluidattacks.com/advisories/blechacz/
https://www.kashipara.com/

Copyright 2024, cxsecurity.com

 

Back to Top