Web / CMS

SQL / NoSQL Injection

SQL injection in School Management System 1.0

SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.

9.8
/ 10
Critical
CVSS v3.1
ADVISORY ID
PS57
PUBLISHED
2023-02-06
CVE IDs
CVE-2022-2054, CVE-2022-36193
VENDORS
lahirudanushka
PUBLIC EXPLOIT
PoC public
CWE
CWE-89, CWE-94
PRODUCT
School Management System 1.0 (PHP/MySQL)
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.

SQL injection in School Management System 1.0 in GitHub repo lahirudanushka/School-Management-System—PHP-MySQL allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.

' or '1'='1′ # ,

' or 1=1;#

Vulnerability details

Vulnerability details

CVE-2022-2054
CWE-94
High | 8.4

SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.

Auth:
None (local access)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
CVE-2022-36193
CWE-89
Critical | 9.8

Same SQL injection reported under a second identifier. Remote attackers modify or delete data through malicious SQL queries.

Auth:
None (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2022-08-05 Reported On

2022-08-30 Made Public On

Fixed On: Not Fixed

Credits

Soummya Mukhopadhyay