PT-2022-21034 · Unknown · Badminton Center Management System

Published

2022-06-02

·

Updated

2022-06-10

·

CVE-2022-32005

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Badminton Center Management System version 1.0
Description The issue allows for SQL Injection via the id parameter in the API endpoint "/admin/services/manage service.php". This could potentially lead to unauthorized access to sensitive data.
Recommendations For Badminton Center Management System version 1.0, consider restricting access to the /admin/services/manage service.php endpoint until a patch is available, and avoid using the id parameter in this endpoint to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-32005

Affected Products

Badminton Center Management System