CVE-2019-14754

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
08/08/2019
Last modified:
14/08/2019

Description

Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:open-school:open-school:2.3:*:*:*:community:*:*:*
cpe:2.3:a:open-school:open-school:3.0:*:*:*:-:*:*:*


References to Advisories, Solutions, and Tools