PT-2022-11455 · Unknown · Sourcecodester Student Quarterly Grading System

Oretnom23

·

Published

2022-01-24

·

Updated

2022-01-28

·

CVE-2021-41658

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sourcecodester Student Quarterly Grading System (affected versions not specified)
Description The issue allows attackers to execute arbitrary code via the fullname and username parameters to the "users page" API endpoint. This enables the execution of arbitrary code, potentially leading to security breaches.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41658

Affected Products

Sourcecodester Student Quarterly Grading System