PT-2022-25601 · Unknown · Exam Reviewer Management System

Published

2022-09-27

·

Updated

2022-09-28

·

CVE-2022-40877

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Exam Reviewer Management System version 1.0
Description The issue concerns SQL Injection via the id parameter. This allows for potential manipulation of database queries, which could lead to unauthorized data access or modification.
Recommendations For Exam Reviewer Management System version 1.0, consider restricting access to the id parameter to minimize the risk of exploitation. Avoid using the id parameter in sensitive queries until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-40877

Affected Products

Exam Reviewer Management System