add_edu of the file /_parse/_all_edits.php. The manipulation of the argument degree leads to sql injection.The identification of this vulnerability is CVE-2024-12939. The attack may be initiated remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.