Описание
A vulnerability was determined in code-projects Human Resource Integrated System 1.0. This vulnerability affects unknown code of the file /login_query12.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Ссылки
- Product
- ExploitThird Party Advisory
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:code-projects:human_resource_integrated_system:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 11%
0.00039
Низкий
7.3 High
CVSS3
5.3 Medium
CVSS3
7.5 High
CVSS2
Дефекты
CWE-74
CWE-89
EPSS
Процентиль: 11%
0.00039
Низкий
7.3 High
CVSS3
5.3 Medium
CVSS3
7.5 High
CVSS2
Дефекты
CWE-74
CWE-89