CVE-2022-27927
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.
9.8
CVSS
13.8%
EPSS (exploit prob.)
96th
EPSS percentile
2022-04-19
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microfinance_management_system_project | microfinance_management_system | 1.0 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/167017/Microfinance-Management-System-1.0-SQL-Injection.html
- https://github.com/erengozaydin/Microfinance-Management-System-V1.0-SQL-Injection-Vulnerability-Unauthenticated
- https://www.sourcecodester.com/php/14822/microfinance-management-system.html
- http://packetstormsecurity.com/files/167017/Microfinance-Management-System-1.0-SQL-Injection.html
- https://github.com/erengozaydin/Microfinance-Management-System-V1.0-SQL-Injection-Vulnerability-Unauthenticated
- https://www.sourcecodester.com/php/14822/microfinance-management-system.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-27927