PT-2026-7882 · Kostasmitroglou · Password Management Application+1
Sadik Cetin
·
Publicado
2026-02-12
·
Atualizado
2026-03-02
·
CVE-2019-25346
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TheSystem version 1.0
Description
The software contains a SQL injection flaw that enables attackers to bypass authentication. This is achieved by manipulating the
server name parameter to inject malicious SQL code, such as ' or '1=1', allowing unauthorized access to database records and potentially sensitive system information.Recommendations
Apply input validation and sanitization to the
server name parameter to prevent the injection of malicious SQL code.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Password Management Application
Thesystem