Unrated severityNVD Advisory· Published Apr 15, 2020· Updated Sep 17, 2024
ALLE INFORMATION CO., LTD. School Manage System - SQL Injection
CVE-2020-10505
Description
The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of SQL Injection, an attacker can use a union based injection query string to get databases schema and username/password.
Affected products
1- Range: before 2020
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.chtsecurity.com/news/be93c576-e421-489f-9453-a462bdd4c90dmitrex_refsource_CONFIRM
- www.twcert.org.tw/tw/cp-132-3530-53d32-1.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.