CVE-2020-12429: SQL Injection
Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass in the login pages: admin/change-password.php, admin/checkavailability.php, admin/index.php, change-password.php, checkavailability.php, includes/header.php, index.php, and pincode-verification.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12429?
CVE-2020-12429 is a vulnerability in Online Course Registration 2.0 that allows for multiple SQL injections, leading to potential database compromise and authentication bypass.
How severe is CVE-2020-12429?
CVE-2020-12429 has a severity rating of 9.8 (critical) based on the CVSS score.
Which software is affected by CVE-2020-12429?
Online Course Registration 2.0 (version 2.0) is affected by CVE-2020-12429.
How can CVE-2020-12429 be exploited?
CVE-2020-12429 can be exploited through SQL injections in various login pages of Online Course Registration 2.0.
Is there a fix available for CVE-2020-12429?
At the moment, there is no known fix available for CVE-2020-12429. It is recommended to follow official vendor announcements and apply any patches or updates as soon as they are released.