CVE-2022-32399: SQL Injection
Published Jun 24, 2022
·Updated
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/viewcrime.php:4
Affected Software
1 affected component
Prison Management System Project Prison Management System=1.0
Event History
Jun 24, 2022
CVE Published
via MITRE·01:09 AM
Data Sourced
via MITRE·01:09 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-32399?
CVE-2022-32399 is classified as a high-severity SQL injection vulnerability affecting Prison Management System v1.0.
2
How does CVE-2022-32399 affect the Prison Management System?
CVE-2022-32399 allows an attacker to execute arbitrary SQL queries via the 'id' parameter, potentially compromising the database.
3
How do I fix CVE-2022-32399?
To remediate CVE-2022-32399, validate and sanitize user inputs to prevent SQL injection in the application.
4
Is CVE-2022-32399 exploitable remotely?
Yes, CVE-2022-32399 can be exploited remotely if an attacker can access the vulnerable view_crime.php endpoint.
5
What versions of the Prison Management System are affected by CVE-2022-32399?
CVE-2022-32399 affects Prison Management System version 1.0 specifically.