Description
Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can use UNION-based injection to extract sensitive information from the users table including usernames and passwords.
Problem types
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
1.0
Credits
Gnanaraj Mauviel (@0xm3m)
References
www.exploit-db.com/exploits/51845 (ExploitDB-51845)
github.com/Obi08/Enrollment_System (Official Product Homepage)
www.vulncheck.com/...llment-system-10-loginphp-sql-injection