CVE-2021-28423
HIGH 8.8EPSS 2.6%
Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 thru 2.1 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in search.php.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P - EPSS
- 2.58% chance of exploitation in the next 30 days, 84th percentile
- Published
- 2021-07-01
- Updated
- 2025-05-28
Proof-of-concept exploits (3)
- https://nhattruong.blog/2021/05/22/cve-2021-28423-teachers-record-management-system-1-0-s…
- https://packetstormsecurity.com/files/163172/Teachers-Record-Management-System-1.0-SQL-In…
- https://www.exploit-db.com/exploits/50018