E-Learning System 1.0 suffers from an unauthenticated SQL injection vulnerability, which allows remote attackers to execute arbitrary code on the hosting web server and gain a reverse shell.
References
Configurations
History
No history.
Information
Published : 2021-02-15 21:15
Updated : 2024-11-21 06:21
NVD link : CVE-2021-3239
Mitre link : CVE-2021-3239
CVE.ORG link : CVE-2021-3239
JSON object : View
Products Affected
e-learning_system_project
- e-learning_system
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')