SQL Injection Vulnerability in Dairy Farm Shop Management System by PHP Gurukul
CVE-2022-40944
9.8CRITICAL
Key Information:
- Vendor
- PHPgurukul
- Vendor
- CVE Published:
- 30 September 2022
Summary
The Dairy Farm Shop Management System version 1.0 is susceptible to SQL Injection attacks through the sales-report-ds.php file. This vulnerability allows attackers to execute arbitrary SQL commands, potentially leading to unauthorized access to sensitive data within the database. By manipulating input parameters, an attacker can extract, modify, or delete data, compromising the integrity and confidentiality of the information. Proper input validation and prepared statements are essential to mitigate this risk.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved