Vulnerability Description
SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intern Record System Project | Intern Record System | 1.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/171740/Intern-Record-System-1.0-SQL-Injecti
- https://code-projects.org/intern-record-system-in-php-with-source-code/Product
- https://download-media.code-projects.org/2020/03/Intern_Record_System_In_PHP_WitProduct
- https://github.com/h4md153v63n/CVE-2022-40347_Intern-Record-System-phone-V1.0-SQExploitThird Party Advisory
- http://packetstormsecurity.com/files/171740/Intern-Record-System-1.0-SQL-Injecti
- https://code-projects.org/intern-record-system-in-php-with-source-code/Product
- https://download-media.code-projects.org/2020/03/Intern_Record_System_In_PHP_WitProduct
- https://github.com/h4md153v63n/CVE-2022-40347_Intern-Record-System-phone-V1.0-SQExploitThird Party Advisory
FAQ
What is CVE-2022-40347?
CVE-2022-40347 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sen...
How severe is CVE-2022-40347?
CVE-2022-40347 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-40347?
Check the references section above for vendor advisories and patch information. Affected products include: Intern Record System Project Intern Record System.