{ "id": "CVE-2023-5008", "sourceIdentifier": "help@fluidattacks.com", "published": "2023-12-08T00:15:07.597", "lastModified": "2024-11-21T08:40:52.673", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control." }, { "lang": "es", "value": "Student Information System v1.0 es afectado por una vulnerabilidad de inyecci\u00f3n SQL no autenticada en el par\u00e1metro 'regno' de la p\u00e1gina index.php, lo que permite a un atacante externo volcar todo el contenido de la base de datos y evitar el control de inicio de sesi\u00f3n." } ], "metrics": { "cvssMetricV31": [ { "source": "help@fluidattacks.com", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" }, "exploitabilityScore": 3.9, "impactScore": 5.9 } ] }, "weaknesses": [ { "source": "help@fluidattacks.com", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-89" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:imsurajghosh:student_information_system:1.0:*:*:*:*:*:*:*", "matchCriteriaId": "4F523085-89EA-4377-9799-9A0BB43C342D" } ] } ] } ], "references": [ { "url": "https://fluidattacks.com/advisories/blechacz/", "source": "help@fluidattacks.com", "tags": [ "Exploit", "Third Party Advisory" ] }, { "url": "https://www.kashipara.com/", "source": "help@fluidattacks.com", "tags": [ "Product" ] }, { "url": "https://fluidattacks.com/advisories/blechacz/", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Exploit", "Third Party Advisory" ] }, { "url": "https://www.kashipara.com/", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Product" ] } ] }