PT-2019-9631 · Unknown · Attendance Monitoring System

Ihsan Sencan

·

Published

2019-03-17

·

Updated

2019-03-28

·

CVE-2018-18798

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Attendance Monitoring System version 1.0
Description The issue concerns a SQL Injection flaw. It affects the id parameter in several API endpoints: "student/index.php?view=view", "event/index.php?view=view", and "user/index.php?view=view".
Recommendations For Attendance Monitoring System version 1.0, avoid using the id parameter in the affected API endpoints until the issue is resolved. As a temporary workaround, consider restricting access to these endpoints to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18798

Affected Products

Attendance Monitoring System