CVE-2022-30927
Summary
| CVE | CVE-2022-30927 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-06 23:15:00 UTC |
| Updated | 2022-06-14 17:15:00 UTC |
| Description | A SQL injection vulnerability exists in Simple Task Scheduling System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable "id" parameter. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Simple Task Scheduling System Project | Simple Task Scheduling System | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - ykosan1/Simple-Task-Scheduling-System-id-SQL-Injection-Unauthenticated: Badminton Center Management System allows SQL Injection via parameter 'id' in /tss/admin/categories/manage_category.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. | MISC | github.com | |
| Simple Task Scheduling System in PHP/OOP Free Source Code | Free Source Code Projects and Tutorials | MISC | www.sourcecodester.com | |
| www.sourcecodester.com/sites/default/files/download/oretnom23/tss.zip | MISC | www.sourcecodester.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.