Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jpfx-pvpj-qwrq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the attacker could authenticate as Administrator.

Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the attacker could authenticate as Administrator.

EPSS

Процентиль: 79%
0.0131
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.1
nvd
больше 4 лет назад

Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the attacker could authenticate as Administrator.

EPSS

Процентиль: 79%
0.0131
Низкий

Дефекты

CWE-89