CVE-2022-1078
SourceCodester College Website Management System sql injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc with an unknown input leads to sql injection. It is possible to launch the attack remotely and without authentication.
Se ha encontrado una vulnerabilidad en SourceCodester College Website Management System versión 1.0. ha sido clasificada como crítica. El archivo afectado es /cwms/admin/?page=articles/view_article/. La manipulación del argumento id con la entrada " y (select * from(select(sleep(10)))Avx) y "abc" = "abc con una entrada desconocida conlleva a una inyección sql. Es posible lanzar el ataque de forma remota y sin autenticación
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-25 CVE Reserved
- 2022-03-29 CVE Published
- 2023-10-20 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (0)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
College Website Management System Project Search vendor "College Website Management System Project" | College Website Management System Search vendor "College Website Management System Project" for product "College Website Management System" | 1.0 Search vendor "College Website Management System Project" for product "College Website Management System" and version "1.0" | - |
Affected
|