CVE-2022-31348: SQL Injection
Published Jun 1, 2022
·Updated
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/bookings/updatestatus.php?id=.
Affected Software
2 affected components
Online Car Wash Booking System Project Online Car Wash Booking System=1.0
oretnom23 Online Car Wash Booking System=1.0
Event History
Jun 1, 2022
CVE Published
via MITRE·01:33 PM
Data Sourced
via MITRE·01:33 PM
Description
Jun 2, 2022
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-31348?
CVE-2022-31348 is rated as a critical vulnerability due to its potential for SQL Injection exploitation.
2
How do I fix CVE-2022-31348?
To fix CVE-2022-31348, you should implement parameterized queries to prevent SQL injection in the affected file.
3
What are the potential impacts of CVE-2022-31348?
The impact of CVE-2022-31348 includes unauthorized access to the database and the potential manipulation of sensitive data.
4
Which version of the Online Car Wash Booking System is affected by CVE-2022-31348?
CVE-2022-31348 affects version 1.0 of the Online Car Wash Booking System.
5
Is authentication necessary to exploit CVE-2022-31348?
No, authentication is not required to exploit CVE-2022-31348, making it especially dangerous.