CVE Published: 20/12/2023 |
CVE Updated: 16/09/2024 |
CVE Year: 2023 Source: Fluid Attacks |
Vendor: Kashipara Group |
Product: Student Information System Status : PUBLISHED
CVE-2023-5007 Description
Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The \'id\' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H