vendor:
Ingenious School Management System
by:
Giulio Comi
N/A
CVSS
N/A
SQL injection
Unknown
CWE
Product Name: Ingenious School Management System
Affected Version From: 2.3.2000
Affected Version To: 2.3.2000
Patch Exists: NO
Related CWE:
CPE: Unknown
Platforms Tested: Kali Linux 2.0
2017
Ingenious School Management System 2.3.0 – SQL injection
This vulnerability allows an attacker to inject SQL commands (without authentication) in 'friend_index' GET parameter.
Mitigation:
Unknown