CVE-2022-2715
Last modified
CVE-2022-2715 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability has been found in SourceCodester Employee Management System and classified as critical. This vulnerability affects unknown code of the file eloginwel.php. EPSS estimates a 0.69% chance of exploitation in the next 30 days.
Description
A vulnerability has been found in SourceCodester Employee Management System and classified as critical. This vulnerability affects unknown code of the file eloginwel.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-205834 is the identifier assigned to this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Employee Management System Project | Employee Management System | All versions |
References
- https://vuldb.com/?id.205834Third Party Advisory, VDB Entry
- https://vuldb.com/?id.205834Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2715?
How severe is CVE-2022-2715?
How do I fix CVE-2022-2715?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-27140An arbitrary file upload vulnerability in the file upload mo…9.8
- CVE-2022-27145GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a stack-…5.5
- CVE-2022-27146GPAC mp4box 1.1.0-DEV-rev1759-geb2d1e6dd-has a heap-buffer-o…5.5
- CVE-2022-27147GPAC mp4box 1.1.0-DEV-rev1727-g8be34973d-master has a use-af…5.5
- CVE-2022-27148GPAC mp4box 1.1.0-DEV-rev1663-g881c6a94a-master is vulnerabl…5.5
- CVE-2022-27149Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-27152Roku devices running RokuOS v9.4.0 build 4200 or earlier tha…5.7
- CVE-2022-27156Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injecti…5.4
- CVE-2022-27157pearweb < 1.32 is suffers from a Weak Password Recovery Mech…9.8
- CVE-2022-27158pearweb < 1.32 suffers from Deserialization of Untrusted Dat…9.8
- CVE-2022-2716The Beaver Builder – WordPress Page Builder for WordPress is…5.4
- CVE-2022-27161Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admi…9.8
Are you affected by CVE-2022-2715?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
