CVE-2023-1466 – SourceCodester Student Study Center Desk Management System view_student sql injection
https://notcve.org/view.php?id=CVE-2023-1466
A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0. It has been rated as critical. This issue affects the function view_student of the file admin/?page=students/view_student. The manipulation of the argument id with the input 3' AND (SELECT 2100 FROM (SELECT(SLEEP(5)))FWlC) AND 'butz'='butz leads to sql injection. • https://vuldb.com/?ctiid.223325 https://vuldb.com/?id.223325 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2023-1407 – SourceCodester Student Study Center Desk Management System manage_user.php sql injection
https://notcve.org/view.php?id=CVE-2023-1407
A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://s1.ax1x.com/2023/03/15/pp1gd8x.png https://vuldb.com/?ctiid.223111 https://vuldb.com/?id.223111 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •