First published: Fri Apr 08 2022(Updated: )
Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zoo Management System Project Zoo Management System | =1.0 | |
PHPGURUKUL Zoo Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-27992 is high with a CVSS score of 8.8.
CVE-2022-27992 affects Zoo Management System v1.0 by allowing SQL injection attacks through the class_id parameter.
The CWE of CVE-2022-27992 is CWE-89 (SQL Injection).
To fix the SQL injection vulnerability in Zoo Management System v1.0, apply the latest security patch or update provided by the vendor. Additionally, sanitize and validate user input before using it in SQL queries.
Yes, you can find more information about CVE-2022-27992 at the following references: [http://packetstormsecurity.com/files/166648/PHPGurukul-Zoo-Management-System-1.0-SQL-Injection.html](http://packetstormsecurity.com/files/166648/PHPGurukul-Zoo-Management-System-1.0-SQL-Injection.html), [https://github.com/D4rkP0w4r/CVEs/blob/main/Zoo%20Management%20System%20SQLI/POC.md](https://github.com/D4rkP0w4r/CVEs/blob/main/Zoo%20Management%20System%20SQLI/POC.md)