Sourcecodester · Sourcecodester Simple Online Public Access Catalog · CVE-2022-3495
**Name of the Vulnerable Software and Affected Versions**
SourceCodester Simple Online Public Access Catalog version 1.0
**Description**
A critical issue has been discovered, affecting the Admin Login component, specifically the /opac/Actions.php?a=login endpoint. The manipulation of the `username` and `password` arguments leads to SQL injection. This issue can be exploited remotely.
**Recommendations**
For SourceCodester Simple Online Public Access Catalog version 1.0, consider disabling the Admin Login functionality until a fix is available. Restrict access to the /opac/Actions.php?a=login endpoint to minimize the risk of exploitation. Avoid using the `username` and `password` arguments in this endpoint until the issue is resolved.