CVE-2023-48720SQL Injection in PVT Limited Student Result Management System

CWE-89SQL Injection3 documents3 sources
Severity
9.8CRITICALNVD
EPSS
0.2%
top 63.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 21

Description

Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

🔴Vulnerability Details

2
CVEList
Student Result Management System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)2023-12-21
GHSA
GHSA-r664-26m8-f6h9: Student Result Management System v12023-12-21
CVE-2023-48720 — SQL Injection | cvebase