PT-2022-12343 · Salonerp · Salonerp

Published

2022-01-14

·

Updated

2022-01-21

·

CVE-2021-45406

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SalonERP version 3.0.1
Description A SQL injection issue allows an attacker to inject a payload using the sql parameter in a SQL query while generating a report. This can lead to the discovery of the login admin password hash, which can then be decrypted to obtain the plain-text password.
Recommendations For SalonERP version 3.0.1, as a temporary workaround, consider restricting access to the report generation feature until a patch is available. Avoid using the sql parameter in SQL queries to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45406

Affected Products

Salonerp