PT-2022-12352 · Unknown · Sourcecodester Simple Cold Storage Management System

·

CVE-2021-45435

·

Published

2022-01-28

·

Updated

2023-12-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sourcecodester Simple Cold Storage Management System using PHP/OOP version 1.0
Description An SQL Injection issue exists via the username field in "login.php". This allows for potential exploitation. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For Sourcecodester Simple Cold Storage Management System using PHP/OOP version 1.0, consider restricting access to the login.php file or validating and sanitizing the username field to prevent SQL injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45435

Affected Products

Sourcecodester Simple Cold Storage Management System