Vulnerability Description
Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'id' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kashipara | Student Information System | 1.0 |
Related Weaknesses (CWE)
References
- https://fluidattacks.com/advisories/kissin/ExploitThird Party Advisory
- https://www.kashipara.com/Not Applicable
- https://fluidattacks.com/advisories/kissin/ExploitThird Party Advisory
- https://www.kashipara.com/Not Applicable
FAQ
What is CVE-2023-5007?
CVE-2023-5007 is a vulnerability with a CVSS score of 8.8 (HIGH). Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'id' parameter of the marks.php resource does not validate the characters received and they a...
How severe is CVE-2023-5007?
CVE-2023-5007 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-5007?
Check the references section above for vendor advisories and patch information. Affected products include: Kashipara Student Information System.