CVE-2015-10037 is a critical SQL injection vulnerability affecting an unknown part of the ACI_Escola project. This flaw allows an unauthenticated attacker to remotely execute arbitrary SQL commands, potentially leading to full compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its CVSS score of 9.8 (Critical) and FAUCET Risk Score of 78/100 indicate a severe threat. A patch with identifier 34eed1f7b9295d1424912f79989d8aba5de41e9f is available and strongly recommended for immediate application.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2015-03-12CPE matchmatch criteria | cpe:2.3:a:aci_escola_project:aci_escola:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.