PT-2022-18762 · Unknown · Purchase Order Management System

K0Xx11

·

Published

2022-04-21

·

Updated

2022-04-28

·

CVE-2022-28022

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Purchase Order Management System version 1.0
Description A SQL injection issue was found in the Purchase Order Management System. The vulnerability can be exploited via the /purchase order/classes/Master.php API endpoint, specifically through the f parameter set to delete item.
Recommendations For Purchase Order Management System version 1.0, consider restricting access to the /purchase order/classes/Master.php API endpoint, specifically the delete item function, until a patch is available. Avoid using the f parameter set to delete item in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28022

Affected Products

Purchase Order Management System