vendor:
Academy LMS
by:
CraCkEr
8.1
CVSS
CRITICAL
SQL Injection
89, 74, 707
CWE
Product Name: Academy LMS
Affected Version From: Academy LMS 6.2
Affected Version To: Academy LMS 6.2
Patch Exists: NO
Related CWE: CVE-2023-4974
CPE: a:creativeitem:academy_lms:6.2
Platforms Tested: Windows 10 Pro
2023
Academy LMS 6.2 – SQL Injection
SQL injection allows attackers to gain unauthorized access to sensitive data, manipulate data, and disrupt the application, potentially causing financial losses and harm to a company's reputation. In this exploit, the 'price_min' and 'price_max' parameters in the /academy/tutor/filter path are vulnerable to SQL injection.
Mitigation:
To mitigate this SQL injection vulnerability, input validation and parameterized queries should be implemented to prevent unauthorized SQL commands from being executed.