Описание
Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'id' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.
Ссылки
- ExploitThird Party Advisory
- Not Applicable
- ExploitThird Party Advisory
- Not Applicable
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:kashipara:student_information_system:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 28%
0.00098
Низкий
8.8 High
CVSS3
Дефекты
CWE-89
CWE-89
Связанные уязвимости
CVSS3: 9.8
github
около 2 лет назад
Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'id' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.
EPSS
Процентиль: 28%
0.00098
Низкий
8.8 High
CVSS3
Дефекты
CWE-89
CWE-89