Security Advisory

CVE-2020-10505

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-04-15 06:15:21
Last updated 2024-09-17 01:21:26
Assigner twcert
State PUBLISHED

Description

The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of SQL Injection, an attacker can use a union based injection query string to get databases schema and username/password.