PT-2023-15499 · Unknown · Lead Management System

CVE-2022-47864

·

Publicado

2023-01-11

·

Atualizado

2023-01-13

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lead Management System version 1.0
Description The issue concerns SQL Injection via the id parameter in the "removeCategories.php" file. This allows for potential manipulation of database queries.
Recommendations For Lead Management System version 1.0, avoid using the id parameter in the "removeCategories.php" file until a fix is available. As a temporary workaround, consider restricting access to the "removeCategories.php" file to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-47864

Produtos afetados

Lead Management System