Fiche vulnérabilité
CVE-2022-36193 : faille critique lahirudanushka school management system (CVSS 9.8)
Description
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 28 nov. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- lahirudanushka school management system