CVE-2022-3471
MEDIUMSourceCodester Human Resource Management System - SQL Injection via searccity Parameter
Title source: llmDescription
A vulnerability was found in SourceCodester Human Resource Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file city.php. The manipulation of the argument searccity leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-210715.
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://github.com/Hanfu-l/POC-Exp/blob/main/The%20Human%20Resource%20Management%20System%20searccity%20parameter%20is%20injected.pdf
Third Party Advisory
https://vuldb.com/?id.210715
Scores
CVSS v3
6.3
EPSS
0.0047
EPSS Percentile
37.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-89
CWE-707
Status
published
Products (1)
oretnom23/human_resource_management_system
Published
Oct 13, 2022
Tracked Since
Feb 18, 2026