SQL Injection Vulnerability in Dairy Farm Shop Management System by PHP Gurukul
CVE-2022-40944

9.8CRITICAL

Key Information:

Vendor
PHPgurukul
Vendor
CVE Published:
30 September 2022

Summary

The Dairy Farm Shop Management System version 1.0 is susceptible to SQL Injection attacks through the sales-report-ds.php file. This vulnerability allows attackers to execute arbitrary SQL commands, potentially leading to unauthorized access to sensitive data within the database. By manipulating input parameters, an attacker can extract, modify, or delete data, compromising the integrity and confidentiality of the information. Proper input validation and prepared statements are essential to mitigate this risk.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.