Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-35525
HistoryApr 24, 2022 - 12:00 a.m.

Sourcecodester Baby Care System SQL注入漏洞(CNVD-2022-35525)

2022-04-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
11
sourcecodester
baby care system
sql injection vulnerability
united states
sourcecodester community
admin
siteoptions.php
social=remove
sid parameter
validation
attackers
illegal sql commands
sensitive database data

EPSS

0.002

Percentile

54.5%

Sourcecodester Baby Care System is an application of the Sourcecodester community in the United States. Sourcecodester Baby Care System v1.0 contains a SQL injection vulnerability that originates in /admin/siteoptions.php & social=remove & sid= where the sid parameter lacks validation for external input SQL statements and can be exploited by attackers to This vulnerability can be exploited to execute illegal SQL commands to steal sensitive database data.

EPSS

0.002

Percentile

54.5%

Related for CNVD-2022-35525