vendor:
Academy LMS
by:
CraCkEr
8.1
CVSS
CRITICAL
SQL Injection
89, 74, 707
CWE
Product Name: Academy LMS
Affected Version From: 45328
Affected Version To: 45328
Patch Exists: NO
Related CWE: CVE-2023-4974
CPE: a:creativeitem:academy_lms:6.2
Platforms Tested: Windows 10 Pro
2023
Academy LMS 6.2 – SQL Injection
SQL injection in Academy LMS 6.2 allows unauthorized access to sensitive data, data modification, and application crash. This can result in financial losses and harm a company's reputation. An attacker can exploit 'price_min' and 'price_max' parameters in the /academy/tutor/filter path to perform SQL injection attacks.
Mitigation:
To mitigate this vulnerability, input validation and parameterized queries should be implemented. Regular security audits and patch management are essential.