PT-2022-13642 · Sourcecodester · Sourcecodester One Church Management System

Mrempy

·

Published

2022-03-29

·

Updated

2022-04-04

·

CVE-2022-1080

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester One Church Management System version 1.0
Description A critical issue has been identified, affecting the code in the attendancy.php file. The manipulation of the search2 argument leads to SQL injection. This issue can be initiated remotely.
Recommendations For SourceCodester One Church Management System version 1.0, consider restricting access to the attendancy.php file to minimize the risk of exploitation. As a temporary workaround, avoid using the search2 argument in the affected file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1080

Affected Products

Sourcecodester One Church Management System