CVE-2019-16264
Summary
| CVE | CVE-2019-16264 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-16 13:15:00 UTC |
| Updated | 2019-09-17 19:53:00 UTC |
| Description | In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username parameter of the authentication form is vulnerable to SQL injection, allowing attackers to access the database. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Egpp | Sistema Integrado De Gestion Academica | 1 | All | All | All |
| Application | Egpp | Sistema Integrado De Gestion Academica | 1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [CVE-2019-16264] Vulnerabilidad de SQLi en el Sistema Integrado de Gestión Académica de la EGPP – Infayer | MISC | infayer.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.