CVE Published: 07/12/2023 |
CVE Updated: 09/10/2024 |
CVE Year: 2023 Source: Fluid Attacks |
Vendor: Kashipara Group |
Product: Student Information System Status : PUBLISHED
CVE-2023-5008 Description
Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the \'regno\' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H