Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
imvks786 student_management_system Administrator Login Endpoint admin_login.php sql injection
Vulnerability Description
A security flaw has been discovered in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This impacts an unknown function of the file admin/admin_login.php of the component Administrator Login Endpoint. Performing a manipulation of the argument a_usr/a_pwd results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
student_management_system 注入漏洞
Vulnerability Description
student_management_system是Vivek Singh个人开发者的一个学生信息管理工具。 student_management_system存在注入漏洞,该漏洞源于Administrator Login Endpoint组件中admin/admin_login.php文件的未知函数对参数a_usr/a_pwd操作不当,可能导致SQL注入。攻击者可远程发起攻击。
CVSS Information
N/A
Vulnerability Type
N/A