{"api_version":"1","generated_at":"2026-07-23T13:39:24+00:00","cve":"CVE-2019-18344","urls":{"html":"https://cve.report/CVE-2019-18344","api":"https://cve.report/api/cve/CVE-2019-18344.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-18344","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-18344"},"summary":{"title":"CVE-2019-18344","description":"Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page (id or classid parameter).","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-10-23 15:15:00","updated_at":"2020-09-03 12:12:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://www.sevenlayers.com/index.php/262-online-grading-system-1-0-sqli","name":"https://www.sevenlayers.com/index.php/262-online-grading-system-1-0-sqli","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Online Grading System 1.0 SQLi","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-18344","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-18344","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"18344","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"online_grading_system_project","cpe5":"online_grading_system","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"18344","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"online_grading_system_project","cpe5":"online_grading_system","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-18344","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page (id or classid parameter)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.sevenlayers.com/index.php/262-online-grading-system-1-0-sqli","refsource":"MISC","name":"https://www.sevenlayers.com/index.php/262-online-grading-system-1-0-sqli"}]}},"nvd":{"publishedDate":"2019-10-23 15:15:00","lastModifiedDate":"2020-09-03 12:12:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:online_grading_system_project:online_grading_system:1.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"18344","Ordinal":"158718","Title":"CVE-2019-18344","CVE":"CVE-2019-18344","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"18344","Ordinal":"1","NoteData":"Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page (id or classid parameter).","Type":"Description","Title":null},{"CveYear":"2019","CveId":"18344","Ordinal":"2","NoteData":"2019-10-23","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"18344","Ordinal":"3","NoteData":"2019-10-23","Type":"Other","Title":"Modified"}]}}}