PT-2018-18093 · Php Scripts Mall · Php Scripts Mall Schools Alert Management Script
Samiran Santra
·
Publicado
2018-02-28
·
Atualizado
2018-03-18
·
CVE-2018-7477
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PHP Scripts Mall School Management Script version 3.0.4
Description
The issue exists due to SQL Injection in the Username and Password fields. This can be exploited via the /parents/Parent module/parent login.php endpoint, specifically through the
username and password variables.Recommendations
For version 3.0.4, update the parent login.php file to properly sanitize the
username and password variables to prevent SQL Injection attacks. As a temporary workaround, consider restricting access to the /parents/Parent module/parent login.php endpoint until a patch is available.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Php Scripts Mall Schools Alert Management Script