SQL Injection Vulnerability in Purchase Order Management System by Oretnom23
CVE-2022-28022
9.8CRITICAL
Key Information:
- Vendor
- CVE Published:
- 21 April 2022
What is CVE-2022-28022?
A SQL injection vulnerability exists in the Purchase Order Management System v1.0, specifically through the endpoint /purchase_order/classes/Master.php?f=delete_item. An attacker could exploit this weakness to execute arbitrary SQL commands, potentially compromising the database and retrieving sensitive information.
