vendor:
Online Students Management System
by:
George Tsimpidas
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Online Students Management System
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:sourcecodester:online_students_management_system:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04.5 LTS (Bionic Beaver)
2020
Online Students Management System 1.0 – ‘username’ SQL Injections
The files index.php on the main login page, and the index.php on the /admin/ login page does not perform input validation on the regno and username parameters. An attacker can send malicious input in the post request to http://localhost/index.php or either http://localhost/admin/index.php and bypass authentication, extract sensitive information etc.
Mitigation:
Input validation should be performed on the regno and username parameters.