CVE-2018-18795: SQL Injection
Published Nov 16, 2018
·Updated
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
Affected Software
1 affected component
School Event Management System Project School Event Management System=1.0
Event History
Nov 16, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18795?
CVE-2018-18795 is classified as a medium severity vulnerability due to its potential for SQL Injection exploits.
2
How do I fix CVE-2018-18795?
To fix CVE-2018-18795, validate and sanitize all user inputs, particularly the id parameter in the student/index.php and event/index.php files.
3
What systems are affected by CVE-2018-18795?
CVE-2018-18795 affects School Event Management System version 1.0.
4
Can CVE-2018-18795 lead to data breaches?
Yes, CVE-2018-18795 can lead to unauthorized access to sensitive data through SQL Injection attacks.
5
Is CVE-2018-18795 actively exploited in the wild?
There have been reports indicating that CVE-2018-18795 is a known vulnerability that could be exploited in the wild.