First published: Wed Jul 20 2022(Updated: )
A vulnerability was found in SourceCodester Library Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /index.php. The manipulation of the argument RollNo with the input admin' AND (SELECT 2625 FROM (SELECT(SLEEP(5)))MdIL) AND 'KXmq'='KXmq&Password=1231312312 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Library Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2492 is classified as a critical vulnerability.
CVE-2022-2492 affects the manipulation of the RollNo parameter in the /index.php file.
CVE-2022-2492 allows for SQL injection attacks, potentially leading to unauthorized access to the database.
To mitigate CVE-2022-2492, validate and sanitize inputs, and upgrade to a patched version of the Library Management System if available.
CVE-2022-2492 affects Library Management System version 1.0.