CVE-2022-27927
Microfinance Management System 1.0 - SQL Injection
Record summary
CVE-2022-27927 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.
Exploitation context
Proofs of concept
1Repository PoCs
GitHuberengozaydin/Microfinance-Management-System-V1.0-SQL-Injection-Vulnerability-UnauthenticatedRepository PoCby erengozaydinStars: 1Not analyzed1 file
Nuclei templates
1ProjectDiscoveryCRITICALMicrofinance Management System 1.0 - SQL InjectionCVSS 9.8
Microfinance Management System 1.0 is susceptible to SQL Injection.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Apply the latest patch or update provided by the vendor to fix the SQL Injection vulnerability in the Microfinance Management System 1.0.
Source: ProjectDiscovery