go to Content

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center


ALLE INFORMATION CO., LTD. School Manage System - SQL Injection

TVN ID TVN-201912001
CVE ID CVE-2020-10505
CVSS 9.8 (Critical)
Affected Products School Manage System versions prior to 2020
Description The School Manage System, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of SQL Injection, allowing attackers to inject SQL commands into the URL.
Solution Contact ALLE INFORMATION CO., LTD. for vulnerabilities patch.
Credit Jia-Rong Chen
Public Date 2020-04-15