PT-2024-11657 · Abrhilsoft · Abrhilsoft Employee'S Portal

Antón Ortigueira

+1

·

Published

2024-04-08

·

Updated

2025-06-20

·

CVE-2022-43216

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions AbrhilSoft Employee's Portal versions prior to 5.6.2
Description The issue is related to a SQL injection vulnerability found in the login page. This vulnerability can potentially be exploited to extract or modify sensitive data from the database.
Recommendations For versions prior to 5.6.2, update to version 5.6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the login page to minimize the risk of exploitation. Avoid using user-input data directly in SQL queries until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-43216

Affected Products

Abrhilsoft Employee'S Portal