A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/167017/Microfinance-Management-System-1.0-SQL-Injection.html | Exploit Third Party Advisory VDB Entry |
https://github.com/erengozaydin/Microfinance-Management-System-V1.0-SQL-Injection-Vulnerability-Unauthenticated | Exploit Third Party Advisory |
https://www.sourcecodester.com/php/14822/microfinance-management-system.html | Product Third Party Advisory |
http://packetstormsecurity.com/files/167017/Microfinance-Management-System-1.0-SQL-Injection.html | Exploit Third Party Advisory VDB Entry |
https://github.com/erengozaydin/Microfinance-Management-System-V1.0-SQL-Injection-Vulnerability-Unauthenticated | Exploit Third Party Advisory |
https://www.sourcecodester.com/php/14822/microfinance-management-system.html | Product Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:56
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/167017/Microfinance-Management-System-1.0-SQL-Injection.html - Exploit, Third Party Advisory, VDB Entry | |
References | () https://github.com/erengozaydin/Microfinance-Management-System-V1.0-SQL-Injection-Vulnerability-Unauthenticated - Exploit, Third Party Advisory | |
References | () https://www.sourcecodester.com/php/14822/microfinance-management-system.html - Product, Third Party Advisory |
09 Sep 2022, 16:55
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) http://packetstormsecurity.com/files/167017/Microfinance-Management-System-1.0-SQL-Injection.html - Exploit, Third Party Advisory, VDB Entry |
11 May 2022, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
27 Apr 2022, 17:31
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/erengozaydin/Microfinance-Management-System-V1.0-SQL-Injection-Vulnerability-Unauthenticated - Exploit, Third Party Advisory | |
References | (MISC) https://www.sourcecodester.com/php/14822/microfinance-management-system.html - Product, Third Party Advisory | |
CWE | CWE-89 | |
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 9.8 |
CPE | cpe:2.3:a:microfinance_management_system_project:microfinance_management_system:1.0:*:*:*:*:*:*:* |
19 Apr 2022, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-04-19 13:15
Updated : 2024-11-21 06:56
NVD link : CVE-2022-27927
Mitre link : CVE-2022-27927
CVE.ORG link : CVE-2022-27927
JSON object : View
Products Affected
microfinance_management_system_project
- microfinance_management_system
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')