← Advisories

EduSec 4.2.5 Multiple SQL Injection Vulnerabilities

Medium
Advisory ID
ZSL-2016-5326
Release Date
25 May 2016
Vendor
Affected Version
4.2.5
CVE
N/A
Tested On
MySQL/5.5.35-0ubuntu0.12.04.2, Apache/2.4.12 (Ubuntu)
Summary

EduSec has a suite of selective modules specifically tailored to the requirements of education industry. EduSec is engineered and designed considering wide range of management functions within the university. With the use of EduSec, staff can be more accountable as it helps to know the performance of each department in just few seconds. Almost all departments within education industry (e. g. admission, administration, time table, examination, HR, finance etc) can be synchronized and accessed. EduSec helps to assign the responsibilities to employee staff and can reduce time wastage and can speed up the administrative functions. Core functions like admissions, library management, transport management, students’ attendance in short entire range of university functions can be well performed by EduSec.

Description

EduSec suffers from multiple SQL Injection vulnerabilities. Input passed via multiple 'id' GET parameters are not properly sanitised before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.

Proof of Concept
Disclosure Timeline
10.05.2016Vulnerability discovered.
12.05.2016Vendor contacted via contact form.
13.05.2016Vendor contacted again via email.
24.05.2016No response received from the vendor.
25.05.2016Public security advisory released.
Credits
Vulnerability discovered by Bikramaditya Guha
References
Changelog
25.05.2016Initial release
26.05.2016Added reference [1]
27.05.2016Added reference [2] and [3]
28.05.2016Added reference [4]