Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-55743
HistoryJun 09, 2022 - 12:00 a.m.

Online Fire Reporting System SQL Injection Vulnerability (CNVD-2022-55743)

2022-06-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
8
online fire reporting system
sql injection
lack of validation
sensitive data
database
carlo montero

EPSS

0.011

Percentile

84.7%

Online Fire Reporting System is an online fire reporting system from Carlo Montero’s personal developer. version v1.0 of Online Fire Reporting System is vulnerable to SQL injection, which originates from /ofrs/admin/?page=user/manage _user&id=Lack of validation of external input SQL statements, an attacker can use the vulnerability to execute illegal SQL commands to steal sensitive data from the database.

EPSS

0.011

Percentile

84.7%

Related for CNVD-2022-55743