Security Advisory

CVE-2023-5010

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-12-20 15:55:07
Last updated 2025-05-19 18:34:51
Assigner Fluid Attacks
State PUBLISHED

Description

Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The coursecode parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.