PT-2021-24138 · Unknown · Online Enrollment Management System
Published
2021-12-23
·
Updated
2022-01-04
·
CVE-2021-44599
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Online Enrollment Management System version 1.0
Description:
The issue allows for SQL injection attacks through the
id parameter. An attacker can craft a payload that injects a SQL sub-query, utilizing MySQL's load file function with a UNC file path referencing a URL on an external domain. This results in the application interacting with the external domain, indicating successful execution of the injected SQL query. The attacker can retrieve sensitive information for all users of the system.Recommendations:
For Online Enrollment Management System version 1.0, consider restricting access to the
id parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the id parameter in sensitive operations until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Online Enrollment Management System