{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-5395","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2024-05-26T08:50:06.296Z","datePublished":"2024-05-27T02:31:03.686Z","dateUpdated":"2024-08-01T21:11:12.574Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2024-05-27T02:31:03.686Z"},"title":"itsourcecode Online Student Enrollment System listofinstructor.php sql injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-89","lang":"en","description":"CWE-89 SQL Injection"}]}],"affected":[{"vendor":"itsourcecode","product":"Online Student Enrollment System","versions":[{"version":"1.0","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file listofinstructor.php. The manipulation of the argument FullName leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-266309 was assigned to this vulnerability."},{"lang":"de","value":"Eine Schwachstelle wurde in itsourcecode Online Student Enrollment System 1.0 ausgemacht. Sie wurde als kritisch eingestuft. Hierbei geht es um eine nicht exakt ausgemachte Funktion der Datei listofinstructor.php. Durch Beeinflussen des Arguments FullName mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":6.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":6.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":6.5,"vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P"}}],"timeline":[{"time":"2024-05-26T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2024-05-26T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2024-05-26T10:55:25.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"Lanxiy7th (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.266309","name":"VDB-266309 | itsourcecode Online Student Enrollment System listofinstructor.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.266309","name":"VDB-266309 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.344622","name":"Submit #344622 | Itsourcecode Online Student Enrollment System Project In PHP 1.0 listofinstructor.php SQL injection","tags":["third-party-advisory"]},{"url":"https://github.com/Lanxiy7th/lx_CVE_report-/issues/8","tags":["exploit","issue-tracking"]}]},"adp":[{"affected":[{"vendor":"online_student_enrollment_system_project","product":"online_student_enrollment_system","cpes":["cpe:2.3:a:online_student_enrollment_system_project:online_student_enrollment_system:1.0:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1.0","status":"affected"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-07-23T18:41:27.855706Z","id":"CVE-2024-5395","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-25T16:54:20.830Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T21:11:12.574Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.266309","name":"VDB-266309 | itsourcecode Online Student Enrollment System listofinstructor.php sql injection","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.266309","name":"VDB-266309 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required","x_transferred"]},{"url":"https://vuldb.com/?submit.344622","name":"Submit #344622 | Itsourcecode Online Student Enrollment System Project In PHP 1.0 listofinstructor.php SQL injection","tags":["third-party-advisory","x_transferred"]},{"url":"https://github.com/Lanxiy7th/lx_CVE_report-/issues/8","tags":["exploit","issue-tracking","x_transferred"]}]}]}}