github.com
https://github.com/atoz-chevara/cve/blob/main/2024/ASIS_AplikasiSistemSekolah_Using_CodeIgniter3-SQL_Injection_Authentication_Bypass.md CVE-2024-45622
CRITICALNuclei
ASIS - SQL Injection Authentication Bypass
Record summary
CVE-2024-45622 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 3, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | 3.0.0 to < 3.2.0 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALASIS - SQL Injection Authentication BypassCVSS 9.8
ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass.
Impact
Unauthenticated attackers can bypass authentication via SQL injection to gain unauthorized access to the ASIS system.
Remediation
Update ASIS to a version later than 3.2.0 that patches the SQL injection vulnerability.
WeaknessesCWE-89
Authorss4e-io
Template tagscvecve2024asisauth-bypasssqlivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:asis:asis:*:*:*:*:*:*:*:*
Google: ASIS | Aplikasi Sistem Sekolah
https://github.com/atoz-chevara/cve/blob/main/2024/ASIS_AplikasiSistemSekolah_Using_CodeIgniter3-SQL_Injection_Authentication_Bypass.md https://packetstormsecurity.com/files/181355/ASIS-3.2.0-SQL-Injection.html https://nvd.nist.gov/vuln/detail/CVE-2024-45622
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-45622