PT-2022-22448 · Sourcecodester · Sourcecodester Simple Online Public Access Catalog

Vijayreddy

·

Published

2022-10-14

·

Updated

2022-10-15

·

CVE-2022-3495

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SourceCodester Simple Online Public Access Catalog version 1.0
Description A critical issue has been discovered, affecting the Admin Login component, specifically the /opac/Actions.php?a=login endpoint. The manipulation of the username and password arguments leads to SQL injection. This issue can be exploited remotely.
Recommendations For SourceCodester Simple Online Public Access Catalog version 1.0, consider disabling the Admin Login functionality until a fix is available. Restrict access to the /opac/Actions.php?a=login endpoint to minimize the risk of exploitation. Avoid using the username and password arguments in this endpoint until the issue is resolved.

Exploit

Fix

Improper Neutralization

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-3495

Affected Products

Sourcecodester Simple Online Public Access Catalog