CVE-2022-2656
published 2022-08-04CVE-2022-2656: A vulnerability classified as critical has been found in SourceCodester Multi Language Hotel Management Software. Affected is an unknown function. The…
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.65%
47.1th percentile
A vulnerability classified as critical has been found in SourceCodester Multi Language Hotel Management Software. Affected is an unknown function. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205596.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sourcecodester | multi_language_hotel_management_software | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hg47-jxwx-xqg5: A vulnerability classified as critical has been found in SourceCodester Multi Language Hotel Management Software
ghsa_unreviewed·2022-08-05
CVE-2022-2656 [CRITICAL] CWE-89 GHSA-hg47-jxwx-xqg5: A vulnerability classified as critical has been found in SourceCodester Multi Language Hotel Management Software
A vulnerability classified as critical has been found in SourceCodester Multi Language Hotel Management Software. Affected is an unknown function. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205596.
GHSA
Jenkins Pipeline: Groovy Plugin has Insufficiently Protected Credentials
ghsa·2022-02-16
CVE-2022-25180 [MEDIUM] CWE-319 Jenkins Pipeline: Groovy Plugin has Insufficiently Protected Credentials
Jenkins Pipeline: Groovy Plugin has Insufficiently Protected Credentials
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in replayed builds.
This allows attackers with Run/Replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.
Pipeline: Groovy Plugin 2656.vf7a_e7b_75a_457 does not allow builds containing password parameters to be replayed.
GHSA
Improper Neutralization of Special Elements used in an OS Command in Jenkins Pipeline: Groovy Plugin
ghsa·2022-02-16
CVE-2022-25173 [HIGH] CWE-78 Improper Neutralization of Special Elements used in an OS Command in Jenkins Pipeline: Groovy Plugin
Improper Neutralization of Special Elements used in an OS Command in Jenkins Pipeline: Groovy Plugin
Jenkins Pipeline: Groovy Plugin prior to 2656.vf7a_e7b_75a_457, 2.94.1, and 2.92.1 uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-04
Published