Obi08-Enrollment System 1.0 login.php SQL Injection
Vulnerability Description
Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can use UNION-based injection to extract sensitive information from the users table including usernames and passwords.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-58276
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Gnanaraj Mauviel (@0xm3m)
Affected Vendor
Obi08/Enrollment System
View all reports →