SQL Injection Vulnerability in Rail Pass Management System by DiliLearngent
CVE-2023-31936
7.2HIGH
What is CVE-2023-31936?
The Rail Pass Management System v.1.0 has a SQL injection vulnerability that can be exploited by remote attackers. This flaw allows attackers to execute arbitrary code through manipulation of the viewid parameter in the view-pass-detail.php file. Attackers can potentially gain unauthorized access to sensitive data or control the underlying system. Proper input validation and sanitization measures are essential to mitigate this risk.