CVE-2022-2017
SourceCodester Prison Management System Visit view_visit.php sql injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pms/admin/visits/view_visit.php of the component Visit Handler. The manipulation of the argument id with the input 2%27and%201=2%20union%20select%201,2,3,4,5,6,7,user(),database()--+ leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Se ha encontrado una vulnerabilidad en SourceCodester Prison Management System versión 1.0. Ha sido calificada como crítica. Este problema afecta a algún procesamiento desconocido del archivo /pms/admin/visits/view_visit.php del componente Visit Handler. La manipulación del argumento id con la entrada 2%27y%201=2%20union%20select%201,2,3,4,5,6,7,user(),database()--+ conlleva a una inyección sql. El ataque puede iniciarse de forma remota. La explotación ha sido revelada al público y puede ser usada
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-06-07 CVE Reserved
- 2022-06-07 CVE Published
- 2023-12-29 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/ch0ing/vul/blob/main/WebRay.com.cn/Prison%20Management%20System%28SQLI%292.md | X_refsource_misc | |
https://vuldb.com/?id.201365 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Prison Management System Project Search vendor "Prison Management System Project" | Prison Management System Search vendor "Prison Management System Project" for product "Prison Management System" | 1.0 Search vendor "Prison Management System Project" for product "Prison Management System" and version "1.0" | - |
Affected
|