First published: Sun Apr 16 2023(Updated: )
A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Washington I-tech Trainsmart | =r1044 | |
=r1044 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36520 is classified as a high severity SQL injection vulnerability.
To fix CVE-2021-36520, you should validate and sanitize user inputs in the affected evaluation/assign-evaluation?id= URI.
CVE-2021-36520 affects the I-Tech Trainsmart version r1044.
CVE-2021-36520 is a SQL injection vulnerability that allows attackers to execute arbitrary SQL commands.
Yes, exploiting CVE-2021-36520 can potentially lead to unauthorized access and data breaches.