First published: Mon May 27 2024(Updated: )
A vulnerability has been found in itsourcecode Online Student Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file listofsubject.php. The manipulation of the argument subjcode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266305 was assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Student Enrollment | ||
Student Enrollment | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5391 is classified as a critical vulnerability.
CVE-2024-5391 allows for SQL injection via the manipulation of the subjcode argument in listofsubject.php.
To mitigate CVE-2024-5391, validate and sanitize user inputs on the subjcode parameter.
As of now, there is no information regarding an official patch for CVE-2024-5391.
CVE-2024-5391 affects version 1.0 of the Online Student Enrollment System.