SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunction.
                
            References
                    | Link | Resource | 
|---|---|
| http://8sec.cc/index.php/archives/330/ | Broken Link | 
| https://gitee.com/inxeduopen/inxedu/issues/I14DNG | Exploit Issue Tracking Third Party Advisory | 
Configurations
                    Information
                Published : 2023-01-20 11:15
Updated : 2023-01-26 10:41
NVD link : CVE-2020-21152
Mitre link : CVE-2020-21152
JSON object : View
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
                inxedu
- inxedu
 


