Описание
A vulnerability was identified in code-projects Human Resource Integrated System 1.0. This issue affects some unknown processing of the file /login.php. Such manipulation of the argument user/pass leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Ссылки
- Product
- ExploitThird Party Advisory
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:code-projects:human_resource_integrated_system:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 9%
0.00035
Низкий
7.3 High
CVSS3
7.5 High
CVSS3
7.5 High
CVSS2
Дефекты
CWE-74
CWE-89
EPSS
Процентиль: 9%
0.00035
Низкий
7.3 High
CVSS3
7.5 High
CVSS3
7.5 High
CVSS2
Дефекты
CWE-74
CWE-89