Description
SQL injection vulnerability in the DRED virtual campus platform. This vulnerability allows an attacker to retrieve, create, update, and delete data from the database by sending a POST request using the ‘buscame’ parameter in ‘/catalogo_c/catalogo.php’.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
all versions (custom)
Credits
Gonzalo Aguilar García (6h4ack)
References
www.incibe.es/...mpus-platform-diseno-de-recursos-educativos