vendor:
                    Academy LMS
                by:
                    CraCkEr
                8.1
                        CVSS
                    CRITICAL
                    SQL Injection
                    89, 74, 707
                        CWE
                    Product Name: Academy LMS
                    Affected Version From:  45328
                    Affected Version To:  45328
                    Patch Exists: NO
                    Related CWE: CVE-2023-4974
                    CPE:  a:creativeitem:academy_lms:6.2
                    Platforms Tested:  Windows 10 Pro
                    2023
                    Academy LMS 6.2 – SQL Injection
SQL injection in Academy LMS 6.2 allows unauthorized access to sensitive data, data modification, and application crash. This can result in financial losses and harm a company's reputation. An attacker can exploit 'price_min' and 'price_max' parameters in the /academy/tutor/filter path to perform SQL injection attacks.
Mitigation:
					To mitigate this vulnerability, input validation and parameterized queries should be implemented. Regular security audits and patch management are essential.