nhattruong.blog
https://nhattruong.blog/2021/05/22/cve-2021-28423-teachers-record-management-system-1-0-searchdata-error-based-sql-injection-authenticated CVE-2021-28423
HIGH
Teachers Record Management System 1.0 - 'Multiple' SQL Injection (Authenticated)
Record summary
CVE-2021-28423 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 thru 2.1 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in search.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTeachers Record Management System 1.0 - 'Multiple' SQL Injection (Authenticated)ExploitDB exploitby nhattruongNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-28423 packetstormsecurity.com
https://packetstormsecurity.com/files/163172/Teachers-Record-Management-System-1.0-SQL-Injection.html phpgurukul.com
https://phpgurukul.com/teachers-record-management-system-using-php-and-mysql exploit-db.com
https://www.exploit-db.com/exploits/50018