SQL Injection Vulnerability in Student Registration and Fee Payment System by an Unknown Vendor
CVE-2022-31908
7.2HIGH
Key Information:
- Vendor
- CVE Published:
- 16 June 2022
What is CVE-2022-31908?
The Student Registration and Fee Payment System version 1.0 has a SQL Injection vulnerability located in the /scms/student.php file. This vulnerability allows an attacker to manipulate SQL queries, potentially leading to unauthorized access to sensitive data. By exploiting this weakness, malicious users could execute arbitrary SQL commands that compromise the integrity and confidentiality of the database. It is essential for users and administrators of this software to implement adequate security measures and apply necessary updates to mitigate the risks associated with this vulnerability.
