PT-2022-20101 · Unknown · Pharmacy Sales/Inventory System
K0Xx11
·
Published
2022-05-13
·
Updated
2022-05-23
·
CVE-2022-30407
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pharmacy Sales And Inventory System version 1.0
Description
The issue allows for SQL Injection via the /pharmacy-sales-and-inventory-system/manage user.php API endpoint, specifically through the
id variable. This could potentially lead to unauthorized access or manipulation of data.Recommendations
For Pharmacy Sales And Inventory System version 1.0, consider validating and sanitizing user input for the
id variable in the /pharmacy-sales-and-inventory-system/manage user.php endpoint to prevent SQL Injection attacks. As a temporary workaround, restrict access to this endpoint until a proper fix is implemented.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pharmacy Sales/Inventory System