SQL Injection in Chat functionality in Schoolbox

Discovered by Akshay Raj on behalf of The Missing Link Security

Vulnerability Details

Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the authenticated attackers to read, modify, and delete database records.

Affected Versions

Before 23.1.3

Fixed Versions

Fixed in: 23.1.3

