SQL Injection Vulnerability in Attendance and Payroll System by an Unknown Vendor
CVE-2022-28012
8.8HIGH
Key Information:
- Vendor
- CVE Published:
- 21 April 2022
What is CVE-2022-28012?
A SQL injection vulnerability was identified in the Attendance and Payroll System version 1.0, specifically within the component located at /admin/position_delete.php. This vulnerability allows attackers to manipulate SQL queries, potentially compromising the database integrity and exposing sensitive data. Proper sanitization and validation of user inputs are essential to mitigate this risk.
