Open ISES Project
- <= 3.30A
A SQL injection vulnerability has been identified in the Open ISES Project version 3.30A. This vulnerability allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious payloads through the 'id' parameter. Exploitation of this vulnerability can lead to the extraction of sensitive database information, including schema names and other data. The vulnerability exists in the 'ajax/form_post.php' endpoint.
Exploitation of this vulnerability allows for arbitrary SQL execution, which can be used to extract sensitive database information or manipulate the database in unauthorized ways.
The vulnerability can be reproduced by sending a GET request to the 'ajax/form_post.php' endpoint with a crafted SQL payload in the 'id' parameter. The injected SQL code can be used to extract database information, such as schema names, through SQL injection techniques.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.