CVE-2022-26293
CRITICALOnline Project Time Management System v1.0 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-26293. PoCs published by Felipe Alcantara.
AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in Online Project Time Management System 1.0. The PoC includes a time-based blind SQLi payload targeting the 'id' parameter in a POST request to update employee data.
Description
Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the function save_employee at /ptms/classes/Users.php.
Exploits (1)
This exploit demonstrates an authenticated SQL injection vulnerability in Online Project Time Management System 1.0. The PoC includes a time-based blind SQLi payload targeting the 'id' parameter in a POST request to update employee data.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H