CVE-2023-6658: SourceCodester Simple Student Attendance System sql injection
Published Dec 10, 2023
·Updated
A vulnerability classified as critical was found in SourceCodester Simple Student Attendance System 1.0. This vulnerability affects unknown code of the file ajax-api.php?action=saveattendance. The manipulation of the argument classid leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247366 is the identifier assigned to this vulnerability.
Affected Software
1 affected component
oretnom23 Simple Student Attendance System=1.0
Event History
Dec 10, 2023
CVE Published
11:00 PM
Data Sourced
11:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-6658?
CVE-2023-6658 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2023-6658?
CVE-2023-6658 is an SQL injection vulnerability.
3
How do I fix CVE-2023-6658?
To fix CVE-2023-6658, sanitize and validate user inputs to prevent SQL injection.
4
Which software is affected by CVE-2023-6658?
CVE-2023-6658 affects SourceCodester Simple Student Attendance System version 1.0.
5
What component of the software is vulnerable in CVE-2023-6658?
The vulnerability affects the ajax-api.php file in the save_attendance action.