Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5v64-89vr-vpwr

Опубликовано: 09 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username and password fields, enabling SQL Injection attacks.

Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username and password fields, enabling SQL Injection attacks.

EPSS

Процентиль: 50%
0.00269
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username and password fields, enabling SQL Injection attacks.

EPSS

Процентиль: 50%
0.00269
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89