PT-2024-22587 · Unknown · Student Information Chatbot

4Xpl0R3R

·

Published

2024-03-11

·

Updated

2025-03-27

·

CVE-2024-28816

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Student Information Chatbot version a0196ab
Description The issue allows SQL injection via the username to the login function in index.php. This can potentially lead to unauthorized access to sensitive data.
Recommendations For version a0196ab, consider disabling the login function in index.php until a patch is available to prevent SQL injection via the username. Restrict access to the index.php file to minimize the risk of exploitation. Avoid using the username variable in the affected login function until the issue is resolved.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-28816

Affected Products

Student Information Chatbot