SQL injection vulnerability exists in the school information query interface (repschoolproj.php) of the EMS 6.2 system of the Office of the Thai Basic Education Commission, which can lead to data leakage.
References
Link | Resource |
---|---|
http://eme1.obec.go.th | Broken Link |
http://eme1.obec.go.th/~eme62/repschoolproj.php?claster=school&idarea=648 | Broken Link |
https://github.com/00xdF/emes/blob/main/readme.md | Broken Link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/235480 | Third Party Advisory |
Configurations
Information
Published : 2022-09-06 13:15
Updated : 2022-09-09 09:05
NVD link : CVE-2022-37185
Mitre link : CVE-2022-37185
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
ems_project
- ems