First published: Sat Aug 06 2022(Updated: )
A vulnerability was found in SourceCodester Expense Management System. It has been rated as critical. This issue affects the function fetch_report_credit of the file report.php of the component POST Parameter Handler. The manipulation of the argument from/to leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-205811.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Expense Management System Project Expense Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-2688 is critical with a value of 9.8.
CVE-2022-2688 affects the function fetch_report_credit of the file report.php in the POST Parameter Handler component, leading to SQL injection.
CVE-2022-2688 poses a critical risk due to its severity and potential for SQL injection attacks.
To mitigate CVE-2022-2688, it is recommended to apply the necessary patches or updates provided by the vendor.
Yes, you can find a reference for CVE-2022-2688 at [https://vuldb.com/?id.205811](https://vuldb.com/?id.205811).