Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ppv4-h8g5-c5h4

Опубликовано: 12 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

A vulnerability, which was classified as critical, was found in 1000 Projects Attendance Tracking Management System 1.0. This affects an unknown part of the file /admin/chart1.php. The manipulation of the argument course_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

A vulnerability, which was classified as critical, was found in 1000 Projects Attendance Tracking Management System 1.0. This affects an unknown part of the file /admin/chart1.php. The manipulation of the argument course_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 30%
0.00109
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-74
CWE-89

Связанные уязвимости

CVSS3: 6.3
nvd
12 месяцев назад

A vulnerability, which was classified as critical, was found in 1000 Projects Attendance Tracking Management System 1.0. This affects an unknown part of the file /admin/chart1.php. The manipulation of the argument course_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
fstec
12 месяцев назад

Уязвимость файла /admin/chart1.php системы управления отслеживанием посещаемости 1000 Projects Attendance Tracking Management System, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 30%
0.00109
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-74
CWE-89