CVE-2023-5011: Kashipara Student Information System
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'coursename' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.
Affected products
- Kashipara Student Information System: version 1.0 only
Published 2023-12-20. Last modified 2026-06-17.