Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-74074
HistoryNov 04, 2022 - 12:00 a.m.

Online Diagnostic Lab Management System SQL Injection Vulnerability

2022-11-0400:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
sql injection
online diagnostic lab management system
version v1.0
user parameters
targeted attack
compromise
site security

EPSS

0.001

Percentile

37.7%

Online Diagnostic Lab Management System is an online diagnostic lab management system that provides a variety of diagnostic tasks online. online Diagnostic Lab Management System is vulnerable to SQL injection in version v1.0. The vulnerability stems from the affected version not properly filtering user parameters. A SQL injection vulnerability was discovered in Online Diagnostic Lab Management System containing a SQL injection vulnerability via the id parameter /odlms/classes/Master.php?f=delete_message. An attacker could use this vulnerability to launch a targeted attack against a target and compromise the site system security.

EPSS

0.001

Percentile

37.7%

Related for CNVD-2022-74074