Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-55740
HistoryJun 09, 2022 - 12:00 a.m.

Online Fire Reporting System SQL Injection Vulnerability (CNVD-2022-55740)

2022-06-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
16
online fire reporting system
sql injection
data theft

EPSS

0.001

Percentile

37.9%

Online Fire Reporting System is an online fire reporting system from Carlo Montero’s personal developer. version v1.0 of Online Fire Reporting System is vulnerable to SQL injection, which originates from /ofrs/admin/?page=requests/ view_request&id=Lack of validation of external input SQL statements, an attacker can use the vulnerability to execute illegal SQL commands to steal sensitive data from the database.

EPSS

0.001

Percentile

37.9%

Related for CNVD-2022-55740