PT-2019-15362 · Sourcecodester · Sourcecodester Online Grading System

Published

2019-10-23

·

Updated

2020-09-03

·

CVE-2019-18344

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester Online Grading System version 1.0
Description The issue allows remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page using the id or classid parameter. This is due to an unauthenticated SQL injection vulnerability.
Recommendations For Sourcecodester Online Grading System version 1.0, consider restricting access to the id and classid parameters in the affected pages until a patch is available. As a temporary workaround, avoid using these parameters in the student, instructor, department, room, class, or user page to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18344

Affected Products

Sourcecodester Online Grading System