Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-57767
HistoryMay 16, 2022 - 12:00 a.m.

Simple Client Management System SQL注入漏洞(CNVD-2022-57767)

2022-05-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
13
sql injection
carlo montero
client management

EPSS

0.002

Percentile

54.5%

Simple Client Management System is a simple client management system from Carlo Montero’s personal developer. version 1.0 of Simple Client Management System is vulnerable to SQL injection, which stems from a lack of validation of external input SQL statements in cms/admin?page=client/ The vulnerability is caused by the lack of validation of external input SQL statements in manage_client&id=, which can be exploited by attackers to execute illegal SQL commands to steal sensitive database data.

EPSS

0.002

Percentile

54.5%

Related for CNVD-2022-57767