ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-27927
A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database.

A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.

NVD description · AI analysis pending
9.814% PoC ×2
  • microfinance management system project microfinance management system
CVE-2022-1083
+2 in the same advisory: …1082 …1081
A vulnerability classified as critical has been found in Microfinance Management System.

A vulnerability classified as critical has been found in Microfinance Management System. The manipulation of arguments like customer_type_number/account_number/account_status_number/account_type_number with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc leads to sql injection in multiple files. It is possible to launch the attack remotely.

NVD description · AI analysis pending
9.8
group max
<1%
  • microfinance management system project microfinance management system