ZeroHour

CVE-2022-26285

PoC
CVSS 3.1
9.8 critical
EPSS
2%p80
Published
()
Modified
Description

Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the apply endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.

Vendors
simple client management system project
Products
simple client management system
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.