Blind SQL Injection Vulnerability in Multi-Vendor Online Groceries Management System by Multiple Vendors
CVE-2022-26632
9.8CRITICAL
Key Information:
- Vendor
- CVE Published:
- 20 May 2022
What is CVE-2022-26632?
A blind SQL injection vulnerability has been identified in version 1.0 of the Multi-Vendor Online Groceries Management System. The flaw arises through the id parameter in the /products/view_product.php file, enabling an attacker to manipulate database queries without directly seeing the results. This can lead to unauthorized data access and manipulation, posing a significant security risk to the application and its users.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved