CVE-2022-43318: SQL Injection
Published Nov 7, 2022
·Updated
Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the stateedit parameter at /hrm/state.php.
Affected Software
2 affected components
Human Resource Management System Project Human Resource Management System=1.0
oretnom23 Human Resource Management System=1.0
Event History
Nov 7, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-43318?
CVE-2022-43318 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2022-43318?
To fix CVE-2022-43318, validate and sanitize user input to prevent SQL injection attacks in the stateedit parameter.
3
What software is affected by CVE-2022-43318?
CVE-2022-43318 affects Human Resource Management System version 1.0.
4
What is the potential impact of CVE-2022-43318?
The potential impact of CVE-2022-43318 includes unauthorized database access and data manipulation.
5
Where is CVE-2022-43318 exploited?
CVE-2022-43318 is exploited in the /hrm/state.php page via the stateedit parameter.