Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-09318
HistoryJan 25, 2022 - 12:00 a.m.

SourceCodester Online Leave Management System SQL注入漏洞

2022-01-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
16
sourcecodester online
leave management system
sql injection
vulnerability
filtering
escaping
arbitrary commands
username parameter
cnvd

EPSS

0.002

Percentile

56.8%

SourceCodester Online Leave Management System is an online leave management system. v1 of SourceCodester Online Leave Management System is vulnerable to SQL injection. system/classes/Login.php parameter lacks effective filtering and escaping, which can be exploited to execute arbitrary SQL commands via the username parameter.

EPSS

0.002

Percentile

56.8%

Related for CNVD-2022-09318