S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-4974 Scanner

CVE-2023-4974 scanner - SQL Injection (SQLi) vulnerability in Academy LMS 6.2

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-4974
6.3
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

A vulnerability was found in Academy LMS 6.2. It has been rated as critical. Affected by this issue is some unknown functionality of the file /academy/tutor/filter of the component GET Parameter Handler. The manipulation of the argument price_min/price_max leads to sql injection. The attack may be launched remotely. VDB-239750 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
LMSby Academy
6.2
Updated Sep 10, 2026View on NVD →
Detail

Academy LMS is a Learning Management System designed for educators, tutors, and trainers who want to create and deploy online courses, quizzes and surveys for educational, commercial or corporate purposes. It is a web-based software application that is easy to use and user-friendly. It allows for content creation, assessment, and tracking of learner progress. The software is used by many businesses and educational institutions worldwide.

One critical vulnerability discovered on Academy LMS is CVE-2023-4974. This issue is classified as a critical vulnerability and is located in an unknown functionality of the file "academy/tutor/filter" of the GET Parameter Handler component. The vulnerability allows for SQL injection using the manipulation of the "price_min/price_max" parameter. The attack can be launched remotely. Unfortunately, despite early notice, the vendor has not yet responded to the security breach.

This vulnerability can lead to serious trouble when exploited. If an attacker injects malicious code into the database of the LMS, he or she can extract sensitive data like students' personal information, tutor's login credentials, and other confidential data sets. This breach may lead to fraudulent activities using the stolen information, such as identity theft. Moreover, the hacker may ransom the stolen data, or use the platform to launch further attacks on other systems.

To conclude, as a reader of this article, you can benefit from the pro features offered on the S4E.com platform. This platform provides you with the necessary insights to ensure the security of digital assets. It is essential to invest in these features for your organization's safety and reputation. Take note: protect yourself from vulnerabilities before it's too late.

 

REFERENCES

Solution Advice

Thankfully, there are precautions that can be taken to protect against this vulnerability. Here are some of the measures that can be implemented:

  • Regularly update the Academy LMS to its latest version, which contains the necessary security patch.
  • Use strong and unique passwords for all website accounts.
  • Implement a firewall and web application security software to detect and block any SQL injection attempts.
  • Carry out regular security audits and vulnerability assessments, and address any detected issues immediately.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-4974 scanner - SQL Injection (SQLi) vulnerability in Academy LMS 6.2 | S4E