CVE-2020-12429

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
28/04/2020
Last modified:
05/05/2020

Description

Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass in the login pages: admin/change-password.php, admin/check_availability.php, admin/index.php, change-password.php, check_availability.php, includes/header.php, index.php, and pincode-verification.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpgurukul:online_course_registration:2.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools