Beveiligingsadvies

CVE-2024-58276

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-12-04 20:41:45
Laatst bijgewerkt 2026-08-14 16:49:25
Toegewezen door VulnCheck
CVSS-score 8.7
Status PUBLISHED

Beschrijving

Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can use UNION-based injection to extract sensitive information from the users table including usernames and passwords.