Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-35527
HistoryApr 24, 2022 - 12:00 a.m.

Sourcecodester Baby Care System SQL注入漏洞(CNVD-2022-35527)

2022-04-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
18
sourcecodester community
united states
sql injection
validation
external input
sql statements
admin posts
illegal commands
sensitive data
database

EPSS

0.002

Percentile

54.5%

Sourcecodester Baby Care System is an application of the Sourcecodester community in the United States. Sourcecodester Baby Care System v1.0 contains a SQL injection vulnerability, which originates from the lack of validation of external input SQL statements in the find= parameter of /admin/posts.php, and can be exploited by attackers to execute illegal SQL commands to steal sensitive data from the database. sensitive data.

EPSS

0.002

Percentile

54.5%

Related for CNVD-2022-35527