Lucene search

K
nvd[email protected]NVD:CVE-2023-27041
HistoryMar 16, 2023 - 5:15 p.m.

CVE-2023-27041

2023-03-1617:15:09
CWE-89
web.nvd.nist.gov
2
cve-2023-27041
sql injection
school registration
fee system
vulnerability
edit user

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

52.3%

School Registration and Fee System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at/bilal final/edit_user.php.

Affected configurations

Nvd
Node
school_registration_and_fee_system_projectschool_registration_and_fee_systemMatch1.0
VendorProductVersionCPE
school_registration_and_fee_system_projectschool_registration_and_fee_system1.0cpe:2.3:a:school_registration_and_fee_system_project:school_registration_and_fee_system:1.0:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

52.3%

Related for NVD:CVE-2023-27041