CVE-2023-41524 - SQL Injection in Student Attendance Management System v1 Description Student Attendance Management System v1 contains a SQL injection vulnerability in the file. The parameter is not properly sanitized before being used in SQL queries, allowing remote attackers to manipulate the database and potentially execute arbitrary code or disclose sensitive information. Vulnerability Type SQL Injection Affected Product Product Name: Student Attendance Management System Version: v1 Component: index.php Vendor: GitHub Repository: https://github.com/rickxy/Student-Attendance-Management-System Attack Details Attack Type: Remote Attack Vector: parameter Impact: - Code Execution - Information Disclosure References https://github.com/rickxy/Student-Attendance-Management-System Discoverer Chaima EL BAHRAOUI