The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of SQL Injection, an attacker can use a union based injection query string to get databases schema and username/password.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2020-04-15T06:15:21.457989Z

Updated: 2024-09-17T01:21:26.334Z

Reserved: 2020-03-12T00:00:00

Link: CVE-2020-10505

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-15T07:15:12.050

Modified: 2020-04-30T18:15:13.067

Link: CVE-2020-10505

cve-icon Redhat

No data.