CVE-2024-58276 HIGH

CVE-2024-58276: Obi08-Enrollment System 1.0 login.php SQL Injection

Vendor Obi08/Enrollment System
Product Obi08/Enrollment System
Weakness CWE-89 · SQLi
Published December 4, 2025
Last update April 7, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can use UNION-based injection to extract sensitive information from the users table including usernames and passwords.

Key dates

02Disclosure timeline

December 4, 2025 CVE published
April 7, 2026 Record updated

Related vulnerabilities

04Related CVE