SQL Injection Vulnerability in Student Attendance Management System by Rickxy
CVE-2023-41523

8.8HIGH

Key Information:

Vendor

Rickxy

Vendor
CVE Published:
7 August 2025

What is CVE-2023-41523?

A SQL injection vulnerability was identified in the Student Attendance Management System version 1, allowing malicious actors to exploit the emailAddress parameter in createClassTeacher.php. This vulnerability enables unauthorized access to the system's database, potentially leading to data leakage, manipulation, or deletion. Proper input validation and sanitation measures should be implemented to safeguard against such exploitation.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.