Lucene search

K
cveMitreCVE-2022-40032
HistoryFeb 17, 2023 - 2:15 p.m.

CVE-2022-40032

2023-02-1714:15:15
CWE-89
mitre
web.nvd.nist.gov
46
cve-2022-40032
sql injection
simple task managing system
code execution
data theft
security vulnerability

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.005

Percentile

77.5%

SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in ‘username’ and ‘password’ parameters, allows attackers to execute arbitrary code and gain sensitive information.

Affected configurations

Nvd
Node
simple_task_managing_system_projectsimple_task_managing_systemMatch1.0
VendorProductVersionCPE
simple_task_managing_system_projectsimple_task_managing_system1.0cpe:2.3:a:simple_task_managing_system_project:simple_task_managing_system:1.0:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.005

Percentile

77.5%