Advaya Softech GEMS ERP Portal SQL Injection Vulnerability

Vulnerability

A critical SQL injection vulnerability has been identified in Advaya Softech GEMS ERP Portal version 2.1. The issue resides in the 'userId' parameter of the '/studentLogin/studentLogin.action' endpoint, allowing remote attackers to manipulate database queries. This vulnerability has been publicly disclosed and could be exploited to read, insert, update, or delete database records.

Impact

Exploitation of this vulnerability allows for Boolean-based and time-based blind SQL injection, enabling attackers to read sensitive database information or manipulate database records.

Reproduction

The vulnerability can be reproduced by sending a crafted request to the '/studentLogin/studentLogin.action' endpoint with a malicious 'userId' parameter that includes SQL injection payloads. This can be done manually or using the provided Python script 'GEMS_POC.py', which automates the exploitation process by extracting database information through the SQL injection vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.