PT-2022-17161 · Unknown · Money Transfer Management System

Oscar Uribe

·

Published

2022-03-23

·

Updated

2022-03-29

·

CVE-2022-25222

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Money Transfer Management System version 1.0
Description The issue allows an unauthenticated user to inject SQL queries in the "admin/maintenance/manage branch.php" and "admin/maintenance/manage fee.php" API endpoints via the id parameter.
Recommendations For Money Transfer Management System version 1.0, consider restricting access to the "admin/maintenance/manage branch.php" and "admin/maintenance/manage fee.php" API endpoints to prevent SQL injection attacks via the id parameter until a patch is available. As a temporary workaround, avoid using the id parameter in the affected API endpoints until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25222

Affected Products

Money Transfer Management System