Описание
Digital Crime Report Management System 1.0 contains a critical SQL injection vulnerability affecting multiple login pages that allows unauthenticated attackers to bypass authentication. Attackers can exploit the vulnerability by sending crafted SQL injection payloads in email and password parameters across police, incharge, user, and HQ login endpoints.
EPSS
Процентиль: 42%
0.002
Низкий
8.2 High
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 8.2
github
17 дней назад
Digital Crime Report Management System 1.0 contains a critical SQL injection vulnerability affecting multiple login pages that allows unauthenticated attackers to bypass authentication. Attackers can exploit the vulnerability by sending crafted SQL injection payloads in email and password parameters across police, incharge, user, and HQ login endpoints.
EPSS
Процентиль: 42%
0.002
Низкий
8.2 High
CVSS3
Дефекты
CWE-89