PT-2025-5761 · Unknown · Sourcecodester Responsive E-Learning System

Published

2025-02-05

·

Updated

2025-02-06

·

CVE-2020-36084

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SourceCodester Responsive E-Learning System version 1.0
Description: The issue allows remote attackers to inject a SQL query in the id field of the "/elearning/delete teacher students.php?id=" endpoint. This enables attackers to execute unauthorized SQL commands.
Recommendations: For SourceCodester Responsive E-Learning System version 1.0, consider disabling the id field in the "/elearning/delete teacher students.php?id=" endpoint until a patch is available. Restrict access to the delete teacher students.php module to minimize the risk of exploitation. Avoid using the id parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36084

Affected Products

Sourcecodester Responsive E-Learning System