Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-35528
HistoryApr 24, 2022 - 12:00 a.m.

Sourcecodester Baby Care System SQL注入漏洞(CNVD-2022-35528)

2022-04-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
sourcecodester
baby care system
sql injection
validation
external input
sql statements
pagerole
admin
edit
roleid
exploit
illegal commands
sensitive data
database.

EPSS

0.002

Percentile

54.5%

Sourcecodester Baby Care System is an application of the Sourcecodester community in the United States. Sourcecodester Baby Care System v1.0 is vulnerable to SQL injection, which originates from the lack of validation of external input SQL statements in the roleid parameter in /admin/pagerole.php & action=edit & roleid=. An attacker could exploit the vulnerability to execute illegal SQL commands to steal sensitive database data.

EPSS

0.002

Percentile

54.5%

Related for CNVD-2022-35528