CVE-2022-36256
Summary
| CVE | CVE-2022-36256 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-12 04:15:00 UTC |
| Updated | 2022-09-15 03:50:00 UTC |
| Description | A SQL injection vulnerability in Stocks.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as "productcode". |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Inventorymanagementsystem Project | Inventorymanagementsystem | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GitHub - sazanrjb/InventoryManagementSystem: A software developed using Java SE which provides as easy way to track the products, suppliers, customers as well as purchase and sales information. It also records the stock currently available in the store. | MISC | github.com | |
| Sql Injection Security Issues · Issue #14 · sazanrjb/InventoryManagementSystem · GitHub | MISC | github.com | |
| Public Reference for CVE-2022-36256 · GitHub | MISC | gist.github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.