Vulnerability CVE-2022-40347


Published: 2023-02-17

Description:
SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Intern Record System 1.0 SQL Injection
Hamdi Sevben
06.04.2023

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 References:
https://github.com/h4md153v63n/CVE-2022-40347_Intern-Record-System-phone-V1.0-SQL-Injection-Vulnerability-Unauthenticated
https://download-media.code-projects.org/2020/03/Intern_Record_System_In_PHP_With_Source_Code.zip
https://code-projects.org/intern-record-system-in-php-with-source-code/

Copyright 2024, cxsecurity.com

 

Back to Top