Remote SQL Injection Vulnerability in Code-Projects Student Record System
CVE-2024-9091
9.8CRITICAL
Summary
A significant vulnerability has been identified in the Student Record System developed by Code-Projects, specifically in the functionality of the /index.php file. This vulnerability allows for SQL injection via manipulation of the 'regno' parameter, enabling attackers to execute malicious SQL queries against the database. This exploit can be executed remotely, posing a serious risk to the integrity and confidentiality of sensitive student data stored within the system. The exploit has been publicly disclosed, necessitating immediate action from users of the affected version to mitigate potential security breaches.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published