A vulnerability, which was classified as critical, was found in Advaya Softech GEMS ERP Portal 2.1. This affects an unknown part of the file /studentLogin/studentLogin.action. The manipulation of the argument userId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
| Software | From | Fixed in |
|---|---|---|
| advayasoftech / gems_erp_portal | 2.1 | 2.1.x |