An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allows remote attackers to execute PostgreSQL statements (e.g., SELECT, INSERT, UPDATE, and DELETE) through /Side.php via the syear parameter.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://gitlab.com/francoisjacquet/rosariosis/-/issues/328 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-11-29T21:34:16
Updated: 2024-08-04T04:25:16.300Z
Reserved: 2021-11-29T00:00:00
Link: CVE-2021-44427
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-11-29T22:15:07.533
Modified: 2024-11-21T06:30:57.080
Link: CVE-2021-44427
Redhat
No data.