PT-2022-23832 · Unknown · Alton Management System

Saitamang

·

Published

2022-09-14

·

Updated

2024-11-26

·

CVE-2022-37138

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Loan Management System version 1.0
Description The issue allows unauthorized users to login as Administrator after injecting the username form at the login page, specifically through SQL Injection.
Recommendations For Loan Management System version 1.0, as a temporary workaround, consider restricting access to the login page or disabling the SQL query execution on the username form until a patch is available. Avoid using the username form in the affected login page until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-37138

Affected Products

Alton Management System