CVE-2022-31350: SQL Injection
Published Jun 1, 2022
·Updated
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/managevehicle.php?id=.
Affected Software
2 affected components
Online Car Wash Booking System Project Online Car Wash Booking System=1.0
oretnom23 Online Car Wash Booking System=1.0
Event History
Jun 1, 2022
CVE Published
via MITRE·01:31 PM
Data Sourced
via MITRE·01:31 PM
Description
Jun 2, 2022
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-31350?
CVE-2022-31350 is classified as a medium severity vulnerability due to the potential for SQL injection attacks.
2
How do I fix CVE-2022-31350?
To fix CVE-2022-31350, validate and sanitize user inputs to prevent SQL injection in the vulnerable endpoint.
3
What is vulnerable in CVE-2022-31350?
CVE-2022-31350 affects the Online Car Wash Booking System v1.0, specifically the manage_vehicle.php script.
4
What type of attack does CVE-2022-31350 allow?
CVE-2022-31350 allows attackers to perform SQL injection attacks, potentially compromising the database.
5
Is CVE-2022-31350 being actively exploited?
There is no specific information indicating that CVE-2022-31350 is being actively exploited, but it remains a significant risk.