SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the LessonID parameter.
References
Link | Resource |
---|---|
https://github.com/ganzhi-qcy/cve/issues/4 |
Configurations
No configuration.
History
No history.
Information
Published : 2024-06-17 19:15
Updated : 2024-07-03 02:04
NVD link : CVE-2024-37840
Mitre link : CVE-2024-37840
CVE.ORG link : CVE-2024-37840
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')