CVE-2023-6617: SourceCodester Simple Student Attendance System attendance.php sql injection
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been classified as critical. Affected is an unknown function of the file attendance.php. The manipulation of the argument classid leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247254 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6617?
CVE-2023-6617 is classified as a critical severity vulnerability.
How does CVE-2023-6617 affect the Simple Student Attendance System?
CVE-2023-6617 affects the attendance.php file, allowing for SQL injection through manipulation of the class_id argument.
How do I fix CVE-2023-6617?
To fix CVE-2023-6617, you should validate and sanitize user inputs in the attendance.php file to prevent SQL injection.
Which version of the Simple Student Attendance System is impacted by CVE-2023-6617?
The impacted version of the Simple Student Attendance System is 1.0.
What type of vulnerability is CVE-2023-6617?
CVE-2023-6617 is an SQL injection vulnerability.