First published: Thu Oct 27 2022(Updated: )
A vulnerability classified as critical has been found in SourceCodester Online Medicine Ordering System 1.0. Affected is an unknown function of the file admin/?page=orders/view_order. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. VDB-212346 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sourcecodester Online Medicine Ordering System | =1.0 | |
Sourcecodester Online Medicine Ordering System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3714 is classified as a critical severity vulnerability.
CVE-2022-3714 is an SQL injection vulnerability found in the SourceCodester Online Medicine Ordering System.
To fix CVE-2022-3714, sanitize and validate user input for the 'id' parameter in the affected files.
The vulnerability affects version 1.0 of the SourceCodester Online Medicine Ordering System.
Yes, CVE-2022-3714 can be exploited remotely due to the SQL injection flaw.