Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.
References
Link | Resource |
---|---|
https://github.com/Qrayyy/CVE/blob/main/Billing%20System%20Project%20v1.0/CVE-2022-43215(sql%20in%20getOrderReport.php).md | Exploit Third Party Advisory |
https://www.sourcecodester.com/php/14831/billing-system-project-php-source-code-free-download.html | Product Third Party Advisory |
Configurations
Information
Published : 2022-11-21 17:15
Updated : 2022-11-23 06:57
NVD link : CVE-2022-43215
Mitre link : CVE-2022-43215
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
billing_system_project
- billing_system