Описание
A security vulnerability has been detected in code-projects Student Crud Operation 3.3. Affected is an unknown function of the file delete.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Ссылки
- Product
- ExploitThird Party Advisory
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.3 (включая)
cpe:2.3:a:code-projects:crud_operation_system:*:*:*:*:*:*:*:*
EPSS
Процентиль: 12%
0.0004
Низкий
7.3 High
CVSS3
8.6 High
CVSS3
7.5 High
CVSS2
Дефекты
CWE-74
CWE-89
Связанные уязвимости
CVSS3: 7.3
github
4 месяца назад
A security vulnerability has been detected in code-projects Student Crud Operation 3.3. Affected is an unknown function of the file delete.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
EPSS
Процентиль: 12%
0.0004
Низкий
7.3 High
CVSS3
8.6 High
CVSS3
7.5 High
CVSS2
Дефекты
CWE-74
CWE-89