Severity
7.2HIGH
EPSS
0.3%
top 50.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateJul 7

Description

A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. Affected is an unknown function of the file /admin/?page=inmates/view_inmate of the component Inmate Handler. The manipulation of the argument id with the input 1%27%20and%201=2%20union%20select%201,user(),3,4,5,6,7,8,9,0,database(),2,3,4,5,6,7,8,9,0,1,2,3,4--+ leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:LExploitability: 1.2 | Impact: 3.4

🔴Vulnerability Details

2
GHSA
GHSA-hvvp-wx93-rp9v: A vulnerability classified as critical has been found in SourceCodester Prison Management System 12022-06-10
CVEList
SourceCodester Prison Management System Inmate sql injection2022-06-07

💥Exploits & PoCs

1
Exploit-DB
Windows 10 v21H1 - HTTP Protocol Stack Remote Code Execution2023-07-07

📋Vendor Advisories

17
Oracle
Oracle Oracle Siebel CRM Risk Matrix: eDetailing (PDF Viewer) — CVE-2018-51582022-10-15
CISA
Apple Multiple Products Memory Corruption Vulnerability2022-06-27
CISA
Adobe Acrobat and Reader Double Free Vulnerability2022-06-08
CISA
QNAP NAS File Station Cross-Site Scripting Vulnerability2022-05-24
CISA
LG N1A1 NAS Remote Command Execution Vulnerability2022-03-25

💬Community

2
HackerOne
DNS rebinding in --inspect (insufficient fix of CVE-2022-32212 affecting macOS devices)2023-01-12
HackerOne
DNS rebinding in --inspect (insufficient fix of CVE-2022-32212 affecting macOS devices)2022-09-28
CVE-2022-2018 (HIGH CVSS 7.2) | A vulnerability classified as criti | cvebase.io