CVE-2024-58276

Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can use UNION-based injection to extract sensitive information from the users table including usernames and passwords.
CVSS

No CVSS.

Configurations

No configuration.

History

04 Dec 2025, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-04 21:16

Updated : 2025-12-08 18:27


NVD link : CVE-2024-58276

Mitre link : CVE-2024-58276

CVE.ORG link : CVE-2024-58276


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')