CVE-2024-5391: itsourcecode Online Student Enrollment System listofsubject.php sql injection
A vulnerability has been found in itsourcecode Online Student Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file listofsubject.php. The manipulation of the argument subjcode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266305 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5391?
CVE-2024-5391 is classified as a critical vulnerability.
How does CVE-2024-5391 affect the Online Student Enrollment System?
CVE-2024-5391 allows for SQL injection via the manipulation of the subjcode argument in listofsubject.php.
What can be done to mitigate CVE-2024-5391?
To mitigate CVE-2024-5391, validate and sanitize user inputs on the subjcode parameter.
Is there a patch available for CVE-2024-5391?
As of now, there is no information regarding an official patch for CVE-2024-5391.
Which version of the Online Student Enrollment System is affected by CVE-2024-5391?
CVE-2024-5391 affects version 1.0 of the Online Student Enrollment System.