Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-61443
HistoryJun 27, 2022 - 12:00 a.m.

74cmsSE SQL Injection Vulnerability (CNVD-2022-61443)

2022-06-2700:00:00
China National Vulnerability Database
www.cnvd.org.cn
17
74cmsse
sql injection
php mysql
vulnerability
recruitment system
sql commands
sensitive data
cnvd-2022-61443

EPSS

0.002

Percentile

55.3%

74cmsSE is a free open source professional recruitment system based on PHP MYSQL. 74cmsSE suffers from a SQL injection vulnerability, which originates from a keyword parameter in /home /jobfairol/resumelist that lacks validation for external input SQL statements. An attacker could use this vulnerability to execute illegal SQL commands to steal sensitive database data.

EPSS

0.002

Percentile

55.3%

Related for CNVD-2022-61443