RULE(RULE ID:338026)

Rule General Information
Release Date: 2024-05-16
Rule Name: LMS PHP 1.0 SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: LMS-PHP-byoretnom23-v1.0 has multiple SQL injection vulnerabilities. The vulnerability is caused by the failure to effectively filter the value of the id parameter, and a malicious attacker can perform SQL injection through the vulnerability. This vulnerability is a framework vulnerability and may be related to CVE-2022-42230.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.