CVE-2022-2666: SourceCodester Loan Management System login.php sql injection
A vulnerability has been found in SourceCodester Loan Management System and classified as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-205618 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2666?
CVE-2022-2666 is classified as a critical vulnerability.
What type of vulnerability is CVE-2022-2666?
CVE-2022-2666 is a SQL injection vulnerability found in the login.php file.
How does CVE-2022-2666 affect the Loan Management System?
CVE-2022-2666 allows remote attackers to manipulate the username argument, potentially compromising the database.
How do I fix CVE-2022-2666?
To fix CVE-2022-2666, validate and sanitize user inputs to prevent SQL injection attacks.
Which systems are affected by CVE-2022-2666?
CVE-2022-2666 affects version 1.0 of both the Loan Management System Project and Razormist Loan Management System.