PT-2021-17148 · Unknown · Teachers Record Management System

Published

2021-02-15

·

Updated

2023-11-14

·

CVE-2021-26822

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Teachers Record Management System version 1.0
Description: The issue concerns a SQL injection vulnerability in the searchteacher POST parameter within the search-teacher.php file. This can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks.
Recommendations: For Teachers Record Management System version 1.0, consider disabling the searchteacher parameter in the search-teacher.php file as a temporary workaround until a patch is available. Restrict access to the search-teacher.php file to minimize the risk of exploitation. Avoid using the searchteacher parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2021-26822

Affected Products

Teachers Record Management System