CVE-2023-5010: Kashipara Student Information System

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'coursecode' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.

Affected products

  • Kashipara Student Information System: version 1.0 only

Published 2023-12-20. Last modified 2026-06-17.