CVE-2023-5008

Published Dec 8, 2023

Last updated 6 months ago

Overview

Description
Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.
Source
help@fluidattacks.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

help@fluidattacks.com
CWE-89

Social media

Hype score
Not currently trending

Configurations