CVE-2022-31340: SQL Injection
Published Jun 1, 2022
·Updated
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/tableeditajax.php.
Affected Software
2 affected components
Simple Inventory System Project Simple Inventory System=1.0
Argie Simple Inventory System=1.0
Event History
Jun 1, 2022
CVE Published
via MITRE·01:21 PM
Data Sourced
via MITRE·01:21 PM
Description
Jun 2, 2022
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-31340?
CVE-2022-31340 is classified as a high severity vulnerability due to its potential for SQL injection attacks.
2
How do I fix CVE-2022-31340?
To fix CVE-2022-31340, it is recommended to sanitize and parameterize all SQL queries within the affected Simple Inventory System v1.0.
3
What is the impact of CVE-2022-31340?
The impact of CVE-2022-31340 can lead to unauthorized access to sensitive database information and possible complete compromise of the web application.
4
Which version of Simple Inventory System is affected by CVE-2022-31340?
CVE-2022-31340 specifically affects Simple Inventory System version 1.0.
5
What part of the Simple Inventory System is vulnerable in CVE-2022-31340?
The vulnerability in CVE-2022-31340 lies in the /inventory/table_edit_ajax.php endpoint, which is susceptible to SQL injection.