PT-2022-19722 · Unknown · Universis-Api

Stavros Mekesis

·

Published

2022-04-25

·

Updated

2022-05-04

·

CVE-2022-29603

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions UniverSIS-API versions through 1.2.1
Description A SQL Injection issue exists, allowing a remote authenticated attacker to send crafted SQL statements to vulnerable API endpoints, such as /api/students/me/messages/, via the select parameter. This could potentially lead to the retrieval of personal information or modification of grades.
Recommendations For UniverSIS-API versions through 1.2.1, consider restricting access to the vulnerable API endpoints, such as /api/students/me/messages/, until a fix is available. As a temporary workaround, avoid using the select parameter in affected API endpoints to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29603

Affected Products

Universis-Api