Student Attendance Management System
cpe:2.3:a:student_attendance_management_system_project:student_attendance_management_system:*:*:*:*:*:*:*
- v1
A SQL injection vulnerability has been identified in the Student Attendance Management System version 1. The issue resides in the 'index.php' file, where the 'username' parameter is not properly sanitized before being used in SQL queries. This lack of sanitation allows remote attackers to manipulate database queries, potentially leading to arbitrary code execution or unauthorized disclosure of sensitive information.
Exploitation of this vulnerability allows for SQL injection, which could be used to execute arbitrary SQL commands, potentially leading to unauthorized data access or manipulation. Additionally, according to the vulnerability's discoverer, this could allow for arbitrary code execution.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.