CVE-2022-2688: SourceCodester Expense Management System POST Parameter report.php fetch_report_credit sql injection
A vulnerability was found in SourceCodester Expense Management System. It has been rated as critical. This issue affects the function fetchreportcredit of the file report.php of the component POST Parameter Handler. The manipulation of the argument from/to leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-205811.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2688?
The severity of CVE-2022-2688 is critical with a value of 9.8.
How does CVE-2022-2688 affect SourceCodester Expense Management System?
CVE-2022-2688 affects the function fetch_report_credit of the file report.php in the POST Parameter Handler component, leading to SQL injection.
What is the risk of CVE-2022-2688?
CVE-2022-2688 poses a critical risk due to its severity and potential for SQL injection attacks.
How can I mitigate CVE-2022-2688?
To mitigate CVE-2022-2688, it is recommended to apply the necessary patches or updates provided by the vendor.
Are there any references for CVE-2022-2688?
Yes, you can find a reference for CVE-2022-2688 at [https://vuldb.com/?id.205811](https://vuldb.com/?id.205811).