First published: Fri Sep 29 2023(Updated: )
A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file seed_message_student.php. The manipulation of the argument teacher_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-240910 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Engineers Online Portal | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-5282 is critical with a score of 9.8.
CVE-2023-5282 affects the SourceCodester Engineers Online Portal 1.0 by allowing remote attackers to initiate SQL injection through the manipulation of the 'teacher_id' argument in the 'seed_message_student.php' file.
To fix CVE-2023-5282, it is recommended to apply the latest patch or update provided by the Engineers Online Portal Project for the SourceCodester Engineers Online Portal 1.0.
The Common Weakness Enumeration (CWE) ID associated with CVE-2023-5282 is CWE-89 (SQL Injection).
More information about CVE-2023-5282 can be found at the following references: [1] [2]