vendor:
CollegeManagementSystem-CMS
by:
Cakes
7.5
CVSS
HIGH
SQL Injection
CWE
Product Name: CollegeManagementSystem-CMS
Affected Version From: 1.3
Affected Version To: 1.3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: CentOS 7
2019
CollegeManagementSystem-CMS 1.3 – ‘batch’ SQL Injection
The CollegeManagementSystem-CMS version 1.3 is vulnerable to SQL Injection. The 'batch' parameter is not properly sanitized, allowing attackers to inject malicious SQL code.
Mitigation:
Update to a patched version of CollegeManagementSystem-CMS.