Student Result Management System v1.0 - Multiple Unauthenticated SQL Injections (SQLi)
CVE-2023-48720
What is CVE-2023-48720?
The Student Result Management System version 1.0 contains multiple vulnerabilities that allow for unauthenticated SQL Injection attacks. Specifically, the 'password' parameter of the login.php resource does not properly validate input before it is sent to the database, enabling attackers to exploit this weakness to manipulate database queries. This can lead to unauthorized access to sensitive data and potential data breaches. Organizations using this software should implement immediate patches to safeguard against these vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Student Result Management System 1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
