Record summary

CVE-2021-44427 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 18, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub AdvisoryBefore 8.1.1 · Fixed in 8.1.1affected

Nuclei templates

1
ProjectDiscoveryCRITICALRosario Student Information System Unauthenticated SQL InjectionCVSS 9.8

An unauthenticated SQL injection vulnerability in Rosario Student Information System (aka rosariosis) 8.1 and below allow remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to extract sensitive information from the database, modify data, or execute arbitrary SQL commands.

Remediation

Upgrade to version 8.1.1 or higher.

WeaknessesCWE-89
Authorsfurkansayim, xShuden
Template tagscvecve2021sqlirosariosisvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:rosariosis:rosariosis:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

6