Simple Student Information System是Carlo Montero个人开发者的一个基于网络的应用平台。可以帮助某所大学或学院管理学生的信息和学业记录。 Simple Student Information System存在SQL注入漏洞,该漏洞源于文件manage_course.php的某些未知处理受到影响,对参数id的操作会导致sql注入。攻击可以远程发起,该漏洞利用已向公众披露并可能被使用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Simple Student Information System | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-2715 | 6.3 MEDIUM | SourceCodester Employee Management System eloginwel.php sql injection |
| CVE-2022-2723 | 6.3 MEDIUM | SourceCodester Employee Management System eprocess.php sql injection |
| CVE-2022-2724 | 6.3 MEDIUM | SourceCodester Employee Management System aprocess.php sql injection |
| CVE-2022-2727 | 6.3 MEDIUM | SourceCodester Gym Management System login.php sql injection |
| CVE-2022-2728 | 6.3 MEDIUM | SourceCodester Gym Management System index.php sql injection |
| CVE-2022-2725 | 3.5 LOW | SourceCodester Company Website CMS add-blog.php cross site scripting |
No comments yet