First published: Mon Jan 24 2022(Updated: )
SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Online Learning System Project Online Learning System | =2.0 | |
Oretnom23 Elearning System | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40596 has a medium severity level due to its potential for SQL injection attacks.
To fix CVE-2021-40596, validate and sanitize user inputs, especially the faculty_id parameter.
CVE-2021-40596 can allow attackers to execute arbitrary SQL commands, potentially leading to data breaches.
CVE-2021-40596 specifically affects Online Learning System v2.0.
CVE-2021-40596 was identified in software developed by oretnom23.