Student Management System has SQL Injection vulnerability via $id paremeter in /config/DbFunction.php
.
https://code-projects.org/student-management-system-using-php-source-code/
/config/DbFunction.php - $sid
paremeter.
The SQL Injection vulnerability exists in diretory /config/DbFunction.php
where this function query the subject $sid
parameter into the SQL statement without any restriction, validation or sanitization. An attacker could exploit this vulnerability to get Remote Code Execution (RCE).
function showSubject1($sid){
$db = Database::getInstance();
$mysqli = $db->getConnection();
$query = "SELECT * FROM subject where subid='$sid' ";
$stmt= $mysqli->query($query);
return $stmt;
}