i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A SQL Injection vulnerability was found prior to the 2.9 branch in the `ieducar/intranet/funcionario_vinculo_det.php` file, which creates the query by concatenating the unsanitized GET parameter `cod_func`, allowing the attacker to obtain sensitive information such as emails and password hashes. Commit 7824b95745fa2da6476b9901041d9c854bf52ffe fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 13 Sep 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Fri, 06 Sep 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | i-Educar is free, completely online school management software that allows school secretaries, teachers, coordinators and area managers. In affected versions Creating a SQL query from a concatenation of a user-controlled GET parameter allows an attacker to manipulate the query. Successful exploitation of this flaw allows an attacker to have complete and unrestricted access to the database, with a web user with minimal permissions. This may involve obtaining user information, such as emails, password hashes, etc. This issue has not yet been patched. Users are advised to contact the developer and to coordinate an update schedule. | i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A SQL Injection vulnerability was found prior to the 2.9 branch in the `ieducar/intranet/funcionario_vinculo_det.php` file, which creates the query by concatenating the unsanitized GET parameter `cod_func`, allowing the attacker to obtain sensitive information such as emails and password hashes. Commit 7824b95745fa2da6476b9901041d9c854bf52ffe fixes the issue. |
References |
|
Wed, 28 Aug 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Portabilis
Portabilis i-educar |
|
CPEs | cpe:2.3:a:portabilis:i-educar:*:*:*:*:*:*:*:* | |
Vendors & Products |
Portabilis
Portabilis i-educar |
|
Metrics |
ssvc
|
Wed, 28 Aug 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | i-Educar is free, completely online school management software that allows school secretaries, teachers, coordinators and area managers. In affected versions Creating a SQL query from a concatenation of a user-controlled GET parameter allows an attacker to manipulate the query. Successful exploitation of this flaw allows an attacker to have complete and unrestricted access to the database, with a web user with minimal permissions. This may involve obtaining user information, such as emails, password hashes, etc. This issue has not yet been patched. Users are advised to contact the developer and to coordinate an update schedule. | |
Title | Authenticated SQL Injection in i-Educar | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-08-28T20:17:31.835Z
Updated: 2024-09-06T19:27:25.280Z
Reserved: 2024-08-21T17:53:51.333Z
Link: CVE-2024-45059
Vulnrichment
Updated: 2024-08-28T20:34:58.231Z
NVD
Status : Analyzed
Published: 2024-08-28T21:15:07.473
Modified: 2024-09-13T20:09:19.523
Link: CVE-2024-45059
Redhat
No data.