PT-2019-15362 · Sourcecodester · Sourcecodester Online Grading System

Publicado

2019-10-23

·

Atualizado

2020-09-03

·

CVE-2019-18344

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester Online Grading System version 1.0
Description The issue allows remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page using the id or classid parameter. This is due to an unauthenticated SQL injection vulnerability.
Recommendations For Sourcecodester Online Grading System version 1.0, consider restricting access to the id and classid parameters in the affected pages until a patch is available. As a temporary workaround, avoid using these parameters in the student, instructor, department, room, class, or user page to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-18344

Produtos afetados

Sourcecodester Online Grading System