PT-2022-19008 · Unknown · Home Owners Collection Management System

K0Xx11

·

Published

2022-04-21

·

Updated

2022-04-28

·

CVE-2022-28416

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Home Owners Collection Management System version 1.0
Description A SQL injection issue was found in the Home Owners Collection Management System. The vulnerability can be exploited via the /hocms/classes/Master.php API endpoint, specifically through the f parameter set to delete phase.
Recommendations For Home Owners Collection Management System version 1.0, consider restricting access to the delete phase function in the Master.php file until a patch is available. Avoid using the f parameter in the /hocms/classes/Master.php endpoint with the value delete phase to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28416

Affected Products

Home Owners Collection Management System