A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the function User::AuthenticateUser of the file login.php. Performing manipulation of the argument user_email results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.
| Software | From | Fixed in |
|---|---|---|
| itsourcecode / web-based_internet_laboratory_management_system | 1.0 | 1.0.x |