CVE-2022-2017: SourceCodester Prison Management System Visit view_visit.php sql injection
A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pms/admin/visits/viewvisit.php of the component Visit Handler. The manipulation of the argument id with the input 2%27and%201=2%20union%20select%201,2,3,4,5,6,7,user(),database()--+ leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2017?
CVE-2022-2017 is rated as critical due to the potential for SQL injection attacks.
How do I fix CVE-2022-2017?
To fix CVE-2022-2017, ensure proper input validation and parameterization in the SQL queries used in the Visit Handler.
What components are affected by CVE-2022-2017?
CVE-2022-2017 affects the Visit Handler component within the Prison Management System 1.0.
What systems are vulnerable to CVE-2022-2017?
The vulnerability exists in the Prison Management System Project version 1.0.
What type of vulnerability is CVE-2022-2017?
CVE-2022-2017 is classified as an SQL injection vulnerability.