First published: Thu Aug 18 2022(Updated: )
A SQL injection vulnerability in SupplierDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via parameter searchTxt.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Inventory Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-35601 is rated as critical with a score of 9.8.
Attackers can exploit the vulnerability by executing arbitrary SQL commands via the parameter searchTxt.
The affected software is InventoryManagementSystem version 1.0 by sazanrjb.
Yes, CVE-2022-35601 is associated with CWE-89, which is the SQL Injection vulnerability.