First published: Tue Apr 28 2020(Updated: )
Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass in the login pages: admin/change-password.php, admin/check_availability.php, admin/index.php, change-password.php, check_availability.php, includes/header.php, index.php, and pincode-verification.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Phpgurukul Online Course Registration | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12429 is a vulnerability in Online Course Registration 2.0 that allows for multiple SQL injections, leading to potential database compromise and authentication bypass.
CVE-2020-12429 has a severity rating of 9.8 (critical) based on the CVSS score.
Online Course Registration 2.0 (version 2.0) is affected by CVE-2020-12429.
CVE-2020-12429 can be exploited through SQL injections in various login pages of Online Course Registration 2.0.
At the moment, there is no known fix available for CVE-2020-12429. It is recommended to follow official vendor announcements and apply any patches or updates as soon as they are released.