Skip to main content

eClass SQL Injection Vulnerability

Last Update Date: 30 Jun 2014 10:44 Release Date: 30 Jun 2014 3672 Views

RISK: High Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

A SQL injection vulnerability has been identified in eClass IP (for secondary schools) and eClass Junior (for primary schools), which can be exploited to extract information from the database.


Impact

  • Information Disclosure

System / Technologies affected

  • Versions prior to ip.2.5.5.5.1 (eClass IP) or ej.5.0.4.4.1 (eClass Junior)

Solutions

  • Upgrade to version ip.2.5.5.5.1 (eClass IP) or ej.5.0.4.4.1 (eClass Junior)

Vulnerability Identifier

  • No CVE information is available

Source