First published: Mon Jun 22 2020(Updated: )
Multiple SQL injection vulnerabilities in Sourcecodester Pisay Online E-Learning System 1.0 allow remote unauthenticated attackers to bypass authentication and achieve Remote Code Execution (RCE) via the user_email, user_pass, and id parameters on the admin login-portal and the edit-lessons webpages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Pisay Online E-Learning System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14972 has been classified with a high severity due to its potential for remote code execution.
To fix CVE-2020-14972, it is recommended to update the Sourcecodester Pisay Online E-Learning System to a patched version that addresses these SQL injection vulnerabilities.
The affected system is the Sourcecodester Pisay Online E-Learning System version 1.0.
Yes, CVE-2020-14972 can be exploited remotely by unauthenticated attackers through specific parameters.
The potential impacts of CVE-2020-14972 include unauthorized authentication bypass and remote code execution.