SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php.
References
Link | Resource |
---|---|
https://github.com/Future-Depth/IMS/issues/1 | Exploit Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-02-08 11:15
Updated : 2023-02-18 13:06
NVD link : CVE-2022-45526
Mitre link : CVE-2022-45526
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
institutional_management_website_project
- institutional_management_website