← volver
CVE-2023-5010

Student Information System v1.0 - Multiple Authenticated SQL Injections (SQLi)

CVSS 8.8 HIGHEPSS 0.7%CWE-89
Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'coursecode' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →