CVE-2022-36198: SQL Injection
Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and buspassms/admin/edit-pass-detail.php
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36198?
The severity of CVE-2022-36198 is considered high due to the potential for unauthorized access and data manipulation through SQL injection vulnerabilities.
How do I fix CVE-2022-36198?
To fix CVE-2022-36198, validate and sanitize user inputs, use prepared statements for database queries, and apply updates to the Bus Pass Management System if available.
What systems are affected by CVE-2022-36198?
CVE-2022-36198 affects Bus Pass Management System version 1.0 developed by both Bus Pass Management System Project and Phpgurukul.
How can CVE-2022-36198 be exploited?
CVE-2022-36198 can be exploited by an attacker injecting malicious SQL queries through vulnerable parameters in specified PHP files.
What are the common files involved in CVE-2022-36198?
Common files involved in CVE-2022-36198 include view-enquiry.php, pass-bwdates-reports-details.php, changeimage.php, search-pass.php, edit-category-detail.php, and edit-pass-detail.php.