CVE-2022-37185

SQL injection vulnerability exists in the school information query interface (repschoolproj.php) of the EMS 6.2 system of the Office of the Thai Basic Education Commission, which can lead to data leakage.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ems_project:ems:6.2:*:*:*:*:*:*:*

History

21 Nov 2024, 07:14

Type Values Removed Values Added
References () http://eme1.obec.go.th - Broken Link () http://eme1.obec.go.th - Broken Link
References () http://eme1.obec.go.th/~eme62/repschoolproj.php?claster=school&idarea=648 - Broken Link () http://eme1.obec.go.th/~eme62/repschoolproj.php?claster=school&idarea=648 - Broken Link
References () https://github.com/00xdF/emes/blob/main/readme.md - Broken Link () https://github.com/00xdF/emes/blob/main/readme.md - Broken Link

09 Sep 2022, 16:05

Type Values Removed Values Added
CWE CWE-89
CPE cpe:2.3:a:ems_project:ems:6.2:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References
  • (MISC) https://exchange.xforce.ibmcloud.com/vulnerabilities/235480 - Third Party Advisory
References (MISC) https://github.com/00xdF/emes/blob/main/readme.md - (MISC) https://github.com/00xdF/emes/blob/main/readme.md - Broken Link
References (MISC) http://eme1.obec.go.th/~eme62/repschoolproj.php?claster=school&idarea=648 - (MISC) http://eme1.obec.go.th/~eme62/repschoolproj.php?claster=school&idarea=648 - Broken Link
References (MISC) http://eme1.obec.go.th - (MISC) http://eme1.obec.go.th - Broken Link

06 Sep 2022, 21:39

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-06 20:15

Updated : 2024-11-21 07:14


NVD link : CVE-2022-37185

Mitre link : CVE-2022-37185

CVE.ORG link : CVE-2022-37185


JSON object : View

Products Affected

ems_project

  • ems
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')