Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-68279
HistoryOct 10, 2022 - 12:00 a.m.

Online Leave Management System SQL Injection Vulnerability

2022-10-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
leave management system
sql injection
vulnerability
database
data theft
security issue
sql validation

EPSS

0.001

Percentile

37.7%

Online Leave Management System is an online leave management system. SQL injection vulnerability exists in Online Leave Management System v1.0, which originates in /leave_system/classes/Master.php?f=delete_ department’s id parameter lacks validation for external input SQL statements. An attacker could use this vulnerability to execute illegal SQL commands to steal sensitive database data.

EPSS

0.001

Percentile

37.7%

Related for CNVD-2022-68279