SQL Injection Vulnerability in Attendance and Payroll System by k0xx11
CVE-2022-28008
8.8HIGH
Key Information:
- Vendor
- CVE Published:
- 21 April 2022
What is CVE-2022-28008?
An SQL injection vulnerability exists in the Attendance and Payroll System v1.0 that allows unauthorized users to manipulate database queries through the component /admin/attendance_delete.php. This weakness could lead to unauthorized access to sensitive data and compromise the integrity of the system.
