A vulnerability was found in SourceCodester Online Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file eduauth/edit-class-detail.php. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-222002 is the identifier assigned to this vulnerability.
References
Link | Resource |
---|---|
https://vuldb.com/?ctiid.222002 | Third Party Advisory |
https://vuldb.com/?id.222002 | Third Party Advisory |
https://github.com/E1CHO/cve_hub/blob/main/Online%20student%20management%20system%20pdf/Online%20student%20management%20system%20sql%20vlun%201.pdf |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-02-28 13:15
Updated : 2023-03-13 11:15
NVD link : CVE-2023-1099
Mitre link : CVE-2023-1099
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
online_student_management_system_project
- online_student_management_system