PT-2022-26870 · Unknown · Senayan Library Management System

0Xdc9

·

Published

2022-11-01

·

Updated

2022-11-02

·

CVE-2022-43362

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Senayan Library Management System version 9.4.2
Description The issue is related to a SQL injection vulnerability. It can be exploited via the collType parameter at the "loan by class.php" endpoint.
Recommendations For Senayan Library Management System version 9.4.2, consider restricting access to the loan by class.php endpoint until a patch is available. As a temporary workaround, avoid using the collType parameter in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-43362

Affected Products

Senayan Library Management System