CVE-2022-2708: SourceCodester Gym Management System login.php sql injection
A vulnerability, which was classified as critical, was found in SourceCodester Gym Management System. This affects an unknown part of the file login.php. The manipulation of the argument userlogin with the input 123@xx.com' OR (SELECT 9084 FROM(SELECT COUNT(),CONCAT(0x7178767871,(SELECT (ELT(9084=9084,1))),0x71767a6271,FLOOR(RAND(0)2))x FROM INFORMATIONSCHEMA.PLUGINS GROUP BY x)a)-- dPvW leads to sql injection. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used. The identifier VDB-205833 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2708?
CVE-2022-2708 is a critical vulnerability found in SourceCodester Gym Management System.
How does CVE-2022-2708 affect SourceCodester Gym Management System?
CVE-2022-2708 affects an unknown part of the file login.php in SourceCodester Gym Management System.
What is the severity of CVE-2022-2708?
The severity of CVE-2022-2708 is classified as critical with a severity value of 9.8.
How can CVE-2022-2708 be exploited?
CVE-2022-2708 can be exploited by manipulating the user_login argument with a specific input.
Is there a fix available for CVE-2022-2708?
There is no specific fix available mentioned for CVE-2022-2708. It is recommended to stay updated with the latest version of SourceCodester Gym Management System.