First published: Sat Jan 07 2023(Updated: )
A vulnerability has been found in SourceCodester Loan Management System and classified as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-205618 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Loan Management System | =1.0 | |
Loan Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2666 is classified as a critical vulnerability.
CVE-2022-2666 is a SQL injection vulnerability found in the login.php file.
CVE-2022-2666 allows remote attackers to manipulate the username argument, potentially compromising the database.
To fix CVE-2022-2666, validate and sanitize user inputs to prevent SQL injection attacks.
CVE-2022-2666 affects version 1.0 of both the Loan Management System Project and Razormist Loan Management System.