CVE-2022-27927
Last modified
CVE-2022-27927 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.. EPSS estimates a 13.63% chance of exploitation in the next 30 days.
Description
A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microfinance Management System Project | Microfinance Management System | 1.0 |
References
- http://packetstormsecurity.com/files/167017/Microfinance-Management-System-1.0-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/erengozaydin/Microfinance-Management-System-V1.0-SQL-Injection-Vulnerability-UnauthenticatedExploit, Third Party Advisory
- https://www.sourcecodester.com/php/14822/microfinance-management-system.htmlProduct, Third Party Advisory
- http://packetstormsecurity.com/files/167017/Microfinance-Management-System-1.0-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/erengozaydin/Microfinance-Management-System-V1.0-SQL-Injection-Vulnerability-UnauthenticatedExploit, Third Party Advisory
- https://www.sourcecodester.com/php/14822/microfinance-management-system.htmlProduct, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-27927?
How severe is CVE-2022-27927?
How do I fix CVE-2022-27927?
Are you affected by CVE-2022-27927?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
