PT-2022-16788 · Sourcecodester · Sourcecodester Garage Management System

Xiahao90

·

Published

2022-07-19

·

Updated

2022-07-27

·

CVE-2022-2467

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Garage Management System version 1.0
Description A critical issue has been found in the software, affecting the /login.php file. The manipulation of the username argument with a specific input leads to sql injection. The attack can be initiated remotely.
Recommendations For version 1.0, consider disabling the login functionality until a patch is available to prevent sql injection attacks. Restrict access to the /login.php file to minimize the risk of exploitation. Avoid using the username argument in the affected login endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-2467

Affected Products

Sourcecodester Garage Management System