First published: Thu May 12 2022(Updated: )
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple Client Management System Project Simple Client Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29750 is considered a critical vulnerability due to its potential for SQL Injection leading to unauthorized access to the database.
To fix CVE-2022-29750, sanitize all user inputs and use prepared statements to prevent SQL Injection attacks.
CVE-2022-29750 exploits a SQL Injection vulnerability in the 'delete_service' function within the Master.php file of Simple Client Management System 1.0.
CVE-2022-29750 affects version 1.0 of Simple Client Management System.
The attack vector for CVE-2022-29750 is through the URL endpoint /cms/classes/Master.php?f=delete_service, which allows for SQL Injection.