Uniclare Student Portal SQL Injection Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A SQL injection vulnerability has been identified in Uniclare Student Portal versions 2 and prior. This vulnerability allows remote attackers to execute arbitrary code through the 'Forgot Password' function.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution on the server where Uniclare Student Portal is hosted.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
0.0
threat
0.1
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.