Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page (id or classid parameter).
References
Link | Resource |
---|---|
https://www.sevenlayers.com/index.php/262-online-grading-system-1-0-sqli | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-10-23 08:15
Updated : 2020-09-03 05:12
NVD link : CVE-2019-18344
Mitre link : CVE-2019-18344
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
online_grading_system_project
- online_grading_system