CVE-2023-48716
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 21, 2023
Updated: Dec 29, 2023
CWE ID 89
Summary
CVE-2023-48716: Student Result Management System v1.0 contains unauthenticated SQL Injection vulnerabilities. The 'class_id' parameter of the add_classes.php resource does not undergo proper validation, allowing malicious characters to bypass filters and directly interact with the database. This issue can potentially lead to data manipulation, unauthorized access, or system compromise. Users are advised to update their software promptly to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share