Vulnerability Description
School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious payloads using boolean-based blind SQL injection techniques to the processlogin endpoint to authenticate as administrator without valid credentials.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wecodex | School Management System Cms | 1.0 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/44727ExploitVDB Entry
- https://www.vulncheck.com/advisories/school-management-system-cms-admin-login-sqThird Party Advisory
- https://www.wecodex.com/item/view/school-management-system-in-php-and-mysql/5Broken Link
FAQ
What is CVE-2018-25201?
CVE-2018-25201 is a vulnerability with a CVSS score of 7.1 (HIGH). School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows attackers to bypass authentication by injecting SQL code through the username para...
How severe is CVE-2018-25201?
CVE-2018-25201 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25201?
Check the references section above for vendor advisories and patch information. Affected products include: Wecodex School Management System Cms.