Record summary

CVE-2022-26293 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.

Description

Online Project Time Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the function save_employee at /ptms/classes/Users.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBOnline Project Time Management System 1.0 - SQLi (Authenticated)ExploitDB exploitby Felipe AlcantaraNot analyzed1 file
ExploitDB

PoC details

References

5