CVE-2022-37138: SQL Injection
Published Sep 14, 2022
·Updated
Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form.
Affected Software
2 affected components
Loan Management System Project Loan Management System=1.0
Razormist Loan Management System=1.0
Event History
Sep 14, 2022
CVE Published
via MITRE·03:37 AM
Data Sourced
via MITRE·03:37 AM
Description
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-37138?
CVE-2022-37138 has a high severity rating due to its potential for unauthorized access to the system.
2
How do I fix CVE-2022-37138?
To fix CVE-2022-37138, implement parameterized queries or prepared statements to prevent SQL injection at the login page.
3
Which versions of Loan Management System are affected by CVE-2022-37138?
CVE-2022-37138 affects Loan Management System version 1.0.
4
What type of attack does CVE-2022-37138 enable?
CVE-2022-37138 enables SQL injection attacks allowing unauthorized users to log in as Administrator.
5
Is authentication compromised in CVE-2022-37138?
Yes, CVE-2022-37138 compromises authentication by allowing unauthorized access through SQL injection.