CVE-2022-2705: SourceCodester Simple Student Information System manage_department.php sql injection
A vulnerability was found in SourceCodester Simple Student Information System. It has been rated as critical. This issue affects some unknown processing of the file admin/departments/managedepartment.php. The manipulation of the argument id with the input -5756%27%20UNION%20ALL%20SELECT%20NULL,database(),user(),NULL,NULL,NULL,NULL--%20- leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205829 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2705?
The severity of CVE-2022-2705 is critical with a severity value of 9.8.
How does CVE-2022-2705 affect Simple Student Information System?
CVE-2022-2705 affects Simple Student Information System through the file admin/departments/manage_department.php.
What is the manipulation involved in CVE-2022-2705?
CVE-2022-2705 involves the manipulation of the 'id' argument with the input '-5756%27%20UNION%20ALL%20SELECT%20NULL,data…'
What software is affected by CVE-2022-2705?
The Simple Student Information System Project Simple Student Information System is affected by CVE-2022-2705.
What is the CWE classification of CVE-2022-2705?
CVE-2022-2705 is classified under CWE-89.