Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, username, password, user_id) into SQL queries without validation or parameterization.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
Code-Projects Community Project Scholars Tracking System 安全漏洞
Vulnerability Description
Code-Projects Community Project Scholars Tracking System是Code-Projects开源的一个社区项目学者跟踪系统。 Code-Projects Community Project Scholars Tracking System 1.0版本存在安全漏洞,该漏洞源于/admin/save_user.php和/admin/update_user.php端点缺少身份验证和输入验证,可能导致SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A