PT-2022-23252 · Unknown · School Management System

Soummya Mukhopadhyay

·

Published

2022-11-28

·

Updated

2024-10-17

·

CVE-2022-36193

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions School Management System version 1.0
Description The issue allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
Recommendations For School Management System version 1.0, consider implementing input validation and sanitization to prevent malicious SQL queries from being executed. As a temporary workaround, restrict access to sensitive database operations until a patch is available.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-36193

Affected Products

School Management System