PT-2022-18762 · Unknown · Purchase Order Management System
K0Xx11
·
Published
2022-04-21
·
Updated
2022-04-28
·
CVE-2022-28022
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Purchase Order Management System version 1.0
Description
A SQL injection issue was found in the Purchase Order Management System. The vulnerability can be exploited via the /purchase order/classes/Master.php API endpoint, specifically through the
f parameter set to delete item.Recommendations
For Purchase Order Management System version 1.0, consider restricting access to the /purchase order/classes/Master.php API endpoint, specifically the
delete item function, until a patch is available. Avoid using the f parameter set to delete item in the affected API endpoint until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Purchase Order Management System