PT-2022-20101 · Unknown · Pharmacy Sales/Inventory System

K0Xx11

·

Published

2022-05-13

·

Updated

2022-05-23

·

CVE-2022-30407

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pharmacy Sales And Inventory System version 1.0
Description The issue allows for SQL Injection via the /pharmacy-sales-and-inventory-system/manage user.php API endpoint, specifically through the id variable. This could potentially lead to unauthorized access or manipulation of data.
Recommendations For Pharmacy Sales And Inventory System version 1.0, consider validating and sanitizing user input for the id variable in the /pharmacy-sales-and-inventory-system/manage user.php endpoint to prevent SQL Injection attacks. As a temporary workaround, restrict access to this endpoint until a proper fix is implemented.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-30407

Affected Products

Pharmacy Sales/Inventory System