Back

HIGH

Student Information System v1.0 - Multiple Authenticated SQL Injections (SQLi)

Published Dec 20, 2023

Description

Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'coursecode' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Fluid Attacks
Published Dec 20, 2023
Updated May 19, 2025
Reserved Sep 15, 2023

CISA Vulnrichment

Updated Nov 27, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Fluid Attacks
Published Dec 20, 2023
Updated May 19, 2025

GitHub

No data