CVE-2022-31383: SQL Injection
Published Jun 16, 2022
·Updated
Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.
Affected Software
1 affected component
Phpgurukul Directory Management System=1.0
Event History
Jun 16, 2022
CVE Published
via MITRE·04:41 PM
Data Sourced
via MITRE·04:41 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for Directory Management System v1.0?
The vulnerability ID for Directory Management System v1.0 is CVE-2022-31383.
2
What is the severity level of CVE-2022-31383?
The severity level of CVE-2022-31383 is critical with a score of 9.8.
3
How does the SQL injection vulnerability occur in Directory Management System v1.0?
The SQL injection vulnerability occurs via the editid parameter in view-directory.php in Directory Management System v1.0.
4
What software version is affected by CVE-2022-31383?
The affected software version is Directory Management System v1.0.
5
Is there a proof of concept available for CVE-2022-31383?
Yes, a proof of concept is available at the following link: https://github.com/laotun-s/POC/blob/main/CVE-2022-31383.txt.