Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
halex CourseSEL HTTP GET Parameter IndexController.class.php check_sel sql injection
Vulnerability Description
A security vulnerability has been detected in halex CourseSEL up to 1.1.0. Affected by this vulnerability is the function check_sel of the file Apps/Index/Controller/IndexController.class.php of the component HTTP GET Parameter Handler. The manipulation of the argument seid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
CourseSEL SQL注入漏洞
Vulnerability Description
CourseSEL是Halex个人开发者的一个在线选课系统。 CourseSEL 1.1.0及之前版本存在SQL注入漏洞,该漏洞源于对参数seid的错误操作,可能导致SQL注入。
CVSS Information
N/A
Vulnerability Type
N/A