CVE-2023-5928 is a critical SQL injection vulnerability affecting Campcodes Simple Student Information System 1.0. Specifically, the flaw resides in the /admin/departments/manage_department.php file, where manipulating the 'id' argument allows for unauthorized database access. Rated with a CVSS score of 7.5 (High), this vulnerability can be exploited remotely without authentication, leading to high confidentiality impact by allowing attackers to read sensitive data. The attack complexity is low, making it relatively easy to exploit. While public exploit details are available, there is no evidence of active exploitation in the wild, nor are there Metasploit or Nuclei modules. Community discussion and media coverage are minimal, suggesting limited current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:simple_student_information_system_project:simple_student_information_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.