Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-35524
HistoryApr 24, 2022 - 12:00 a.m.

Sourcecodester Baby Care System SQL注入漏洞(CNVD-2022-35524)

2022-04-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
13
sourcecodester community
united states
baby care system
sql injection
validation
external input
admin
exploit
sensitive data
cnvd-2022-35524

EPSS

0.002

Percentile

54.5%

Sourcecodester Baby Care System is an application of the Sourcecodester community in the United States. Sourcecodester Baby Care System v1.0 contains a SQL injection vulnerability that originates from the lack of validation of external input SQL statements in the userid parameter in /admin/uesrs.php & action=delete & userid=4. An attacker could exploit this vulnerability to execute illegal SQL commands to steal sensitive database data.

EPSS

0.002

Percentile

54.5%

Related for CNVD-2022-35524