A vulnerability was found in SourceCodester Online Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file eduauth/edit-class-detail.php. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-222002 is the identifier assigned to this vulnerability.
References
Link | Resource |
---|---|
https://github.com/E1CHO/cve_hub/blob/main/Online%20student%20management%20system%20pdf/Online%20student%20management%20system%20sql%20vlun%201.pdf | |
https://vuldb.com/?ctiid.222002 | Third Party Advisory |
https://vuldb.com/?id.222002 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
13 Mar 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
Summary | A vulnerability was found in SourceCodester Online Student Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file eduauth/edit-class-detail.php. The manipulation of the argument editid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-222002 is the identifier assigned to this vulnerability. | |
References |
|
06 Mar 2023, 16:37
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://vuldb.com/?ctiid.222002 - Third Party Advisory | |
References | (MISC) https://vuldb.com/?id.222002 - Third Party Advisory | |
CPE | cpe:2.3:a:online_student_management_system_project:online_student_management_system:1.0:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
01 Mar 2023, 13:45
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-02-28 21:15
Updated : 2024-05-17 02:17
NVD link : CVE-2023-1099
Mitre link : CVE-2023-1099
CVE.ORG link : CVE-2023-1099
JSON object : View
Products Affected
online_student_management_system_project
- online_student_management_system
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')