PT-2022-28140 · Sourcecodester · Sourcecodester Loan Management System

Joinia

·

Published

2022-12-30

·

Updated

2024-05-17

·

CVE-2022-4855

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Lead Management System version 1.0
Description A critical issue was found in the SourceCodester Lead Management System. The manipulation of the username argument in the login.php file leads to sql injection. This issue can be exploited remotely.
Recommendations For version 1.0, consider disabling the login functionality until a patch is available to prevent sql injection attacks. Restrict access to the login.php file to minimize the risk of exploitation. Avoid using the username argument in the affected function until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-4855

Affected Products

Sourcecodester Loan Management System