Vulnerability Description
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simple Task Managing System Project | Simple Task Managing System | 1.0 |
Related Weaknesses (CWE)
References
- http://simple.comBroken Link
- https://github.com/xidaner/CVE_HUNTER/blob/main/CVE_09/2022-09-01-SQL2.mdExploitThird Party Advisory
- https://www.sourcecodester.com/php/15624/simple-task-managing-system-php-mysqli-ProductThird Party Advisory
- http://simple.comBroken Link
- https://github.com/xidaner/CVE_HUNTER/blob/main/CVE_09/2022-09-01-SQL2.mdExploitThird Party Advisory
- https://www.sourcecodester.com/php/15624/simple-task-managing-system-php-mysqli-ProductThird Party Advisory
FAQ
What is CVE-2022-40030?
CVE-2022-40030 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.
How severe is CVE-2022-40030?
CVE-2022-40030 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-40030?
Check the references section above for vendor advisories and patch information. Affected products include: Simple Task Managing System Project Simple Task Managing System.