vendor:
Schools Alert Management System
by:
M3@Pandas
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: Schools Alert Management System
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2018-12055
CPE: a:phpscriptsmall:schools_alert_management_system
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=12055, https://www.infosecmatter.com/nessus-plugin-library/?id=12205, https://www.infosecmatter.com/nessus-plugin-library/?id=12065, https://www.infosecmatter.com/nessus-plugin-library/?id=10930, https://www.infosecmatter.com/nessus-plugin-library/?id=15963, https://www.infosecmatter.com/nessus-plugin-library/?id=12052, https://www.infosecmatter.com/nessus-plugin-library/?id=10498, https://www.infosecmatter.com/nessus-plugin-library/?id=15572, https://www.infosecmatter.com/nessus-plugin-library/?id=12209, https://www.infosecmatter.com/nessus-plugin-library/?id=12054
Platforms Tested: Linux Mint
2018
Schools Alert Management Script – SQL Injection
A SQL injection vulnerability exists in Schools Alert Management Script, which allows an attacker to execute arbitrary SQL commands via the 'xxx' parameter in the 'photo_gallery.php' script. This can be exploited to gain access to the database and potentially gain access to sensitive information.
Mitigation:
Input validation should be used to prevent SQL injection attacks. Additionally, the application should use parameterized queries to prevent SQL injection.