PT-2022-22448 · Sourcecodester · Sourcecodester Simple Online Public Access Catalog
Vijayreddy
·
Published
2022-10-14
·
Updated
2022-10-15
·
CVE-2022-3495
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SourceCodester Simple Online Public Access Catalog version 1.0
Description
A critical issue has been discovered, affecting the Admin Login component, specifically the /opac/Actions.php?a=login endpoint. The manipulation of the
username and password arguments leads to SQL injection. This issue can be exploited remotely.Recommendations
For SourceCodester Simple Online Public Access Catalog version 1.0, consider disabling the Admin Login functionality until a fix is available. Restrict access to the /opac/Actions.php?a=login endpoint to minimize the risk of exploitation. Avoid using the
username and password arguments in this endpoint until the issue is resolved.Exploit
Fix
Improper Neutralization
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sourcecodester Simple Online Public Access Catalog