CVE-2023-4974
Academy LMS GET Parameter filter sql injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A vulnerability was found in Academy LMS 6.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument price_min/price_max leads to sql injection. The attack may be launched remotely. VDB-239750 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Se encontró una vulnerabilidad en Academy LMS 6.2. Ha sido calificado como crítico. Una funcionalidad desconocida del archivo /academy/tutor/filter del componente GET Parameter Handler es afectada por esta vulnerabilidad. La manipulación del argumento precio_min/precio_max conduce a la inyección SQL. El ataque puede lanzarse de forma remota. VDB-239750 es el identificador asignado a esta vulnerabilidad. NOTA: Se contactó al proveedor tempranamente sobre esta divulgación, pero no respondió de ninguna manera.
Eine kritische Schwachstelle wurde in Academy LMS 6.2 ausgemacht. Davon betroffen ist unbekannter Code der Datei /academy/tutor/filter der Komponente GET Parameter Handler. Mittels dem Manipulieren des Arguments price_min/price_max mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen.
Academy LMS version 6.2 suffers from a remote SQL injection vulnerability.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-09-14 CVE Reserved
- 2023-09-15 CVE Published
- 2023-09-15 First Exploit
- 2024-08-02 CVE Updated
- 2025-02-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/174681/Academy-LMS-6.2-SQL-Injection.html | Related |
|
https://vuldb.com/?id.239750 | Technical Description |
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/174681 | 2023-09-15 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Creativeitem Search vendor "Creativeitem" | Academy Lms Search vendor "Creativeitem" for product "Academy Lms" | 6.2 Search vendor "Creativeitem" for product "Academy Lms" and version "6.2" | - |
Affected
|