Vulnerability CVE-2023-4974


Published: 2023-09-15   Modified: 2023-09-19

Description:
A vulnerability was found in Academy LMS 6.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument price_min/price_max leads to sql injection. The attack may be launched remotely. VDB-239750 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Academy LMS 6.2 - SQL Injection
CraCkEr
15.09.2023
Med.
Academy LMS 6.2 SQL Injection
CraCkEr
20.09.2023

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 References:
https://vuldb.com/?ctiid.239750
https://vuldb.com/?id.239750
http://packetstormsecurity.com/files/174681/Academy-LMS-6.2-SQL-Injection.html

Copyright 2024, cxsecurity.com

 

Back to Top