CVE-2019-18344

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
23/10/2019
Last modified:
03/09/2020

Description

Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page (id or classid parameter).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:online_grading_system_project:online_grading_system:1.0:*:*:*:*:*:*:*