vendor:
School Management System
by:
Samiran Santra
9.8
CVSS
CRITICAL
SQL Injection
89
CWE
Product Name: School Management System
Affected Version From: 3.0.4
Affected Version To: 3.0.4
Patch Exists: NO
Related CWE: CVE-2018-7477
CPE: a:phpscriptsmall:school_management_system:3.0.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4.
An SQL injection vulnerability exists in PHP Scripts Mall School Management Script 3.0.4. An attacker can exploit this vulnerability by entering a malicious SQL query in the Username and Password fields of the parent_login.php page. This will allow the attacker to login as an admin user.
Mitigation:
Input validation should be used to prevent SQL injection attacks.