First published: Fri Nov 16 2018(Updated: )
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
School Event Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18795 is classified as a medium severity vulnerability due to its potential for SQL Injection exploits.
To fix CVE-2018-18795, validate and sanitize all user inputs, particularly the id parameter in the student/index.php and event/index.php files.
CVE-2018-18795 affects School Event Management System version 1.0.
Yes, CVE-2018-18795 can lead to unauthorized access to sensitive data through SQL Injection attacks.
There have been reports indicating that CVE-2018-18795 is a known vulnerability that could be exploited in the wild.