PT-2019-9524 · Scriptzee · Scriptzee Education Website

Published

2019-06-19

·

Updated

2019-06-20

·

CVE-2018-17840

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Scriptzee Education Website version 1.0
Description A SQL injection issue exists via the subject, city, or country parameter in the college list.html file.
Recommendations For version 1.0, consider restricting access to the college list.html file until a patch is available, and avoid using the subject, city, or country parameters in this context to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17840

Affected Products

Scriptzee Education Website