A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.
References
Link | Resource |
---|---|
https://www.sourcecodester.com/php/14822/microfinance-management-system.html | Product Third Party Advisory |
https://github.com/erengozaydin/Microfinance-Management-System-V1.0-SQL-Injection-Vulnerability-Unauthenticated | Exploit Third Party Advisory |
http://packetstormsecurity.com/files/167017/Microfinance-Management-System-1.0-SQL-Injection.html | Exploit Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-04-19 06:15
Updated : 2022-09-09 09:55
NVD link : CVE-2022-27927
Mitre link : CVE-2022-27927
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
microfinance_management_system_project
- microfinance_management_system