Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-66772
HistorySep 28, 2022 - 12:00 a.m.

Wedding Planner package_detail.php SQL Injection Vulnerability

2022-09-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
wedding planner
sql injection
package_detail.php
validation
external input
sql statements
attacker
database data
security vulnerability

EPSS

0.002

Percentile

54.5%

Wedding Planner is a wedding planner project. Designed to provide users with an easy way to plan their wedding through a web application while using real data, Wedding Planner v1.0 is vulnerable to a SQL injection vulnerability stemming from a missing validation of external input SQL statements in the id parameter in /package_detail.php. An attacker could use this vulnerability to execute illegal SQL commands to steal sensitive database data.

EPSS

0.002

Percentile

54.5%

Related for CNVD-2022-66772