Podatność CVE-2023-6658


Publikacja: 2023-12-10   Modyfikacja: 2023-12-14

Opis:
A vulnerability classified as critical was found in SourceCodester Simple Student Attendance System 1.0. This vulnerability affects unknown code of the file ajax-api.php?action=save_attendance. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247366 is the identifier assigned to this vulnerability.

Typ:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

Affected software
Oretnom23 -> Simple student attendance system 

 Referencje:
https://vuldb.com/?id.247366
https://vuldb.com/?ctiid.247366
https://github.com/daydust/vuln/blob/main/Simple_Student_Attendance_System/ajax-api.php_SQL-injection.md

Copyright 2024, cxsecurity.com

 

Back to Top