PT-2022-26796 · Unknown · Billing System Project

Anewjk

+10

·

Published

2022-11-22

·

Updated

2025-04-29

·

CVE-2022-43215

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Billing System Project version 1.0
Description The issue is related to a SQL injection vulnerability. This vulnerability can be exploited via the endDate parameter at the "getOrderReport.php" endpoint.
Recommendations For Billing System Project version 1.0, consider restricting access to the "getOrderReport.php" endpoint or avoid using the endDate parameter until a fix is available.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-43215

Affected Products

Billing System Project