vendor:
Smart School
by:
CraCkEr
8.1
CVSS
CRITICAL
SQL Injection
89, 74, 707
CWE
Product Name: Smart School
Affected Version From: 6.4.2001
Affected Version To: 36987
Patch Exists: NO
Related CWE: CVE-2023-5495
CPE: a:qdocs:smart_school:6.4.1
Platforms Tested: Windows
2023
Smart School 6.4.1 – SQL Injection
SQL injection can allow unauthorized access to sensitive data, data modification, application crashes, and unavailability, leading to financial loss and reputational damage.
Mitigation:
To mitigate SQL injection vulnerabilities, use parameterized queries, input validation, and escape untrusted input.