RULE(RULE ID:338653)

Rule General Information
Release Date: 2025-01-14
Rule Name: KESION EDU CheckOrder API SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: KESION Online School is an online education platform developed by KESion, which aims to help educational institutions, schools, teachers, enterprises and institutions to quickly carry out online teaching, and provide low-cost and high-quality online education solutions. There is an arbitrary file reading vulnerability in the CheckOrder interface of the system, through which an unauthenticated attacker can read important system files (such as database configuration file, system configuration file), database configuration file, etc., resulting in an extremely insecure website.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.