5.4
CVSSv3

CVE-2018-15918

Published: 05/09/2018 Updated: 05/07/2022
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 555
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

An issue exists in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jorani project jorani 0.6.5

Exploits

# Exploit Title: Jorani Leave Management 065 – 'startdate' SQL Injection # Exploit Author: Javier Olmedo # Website: hackpuntescom # Date: 2018-09-06 # Google Dork: N/A # Vendor: Benjamin BALET # Software Link: joraniorg/downloadhtml # Affected Version: 065 and possibly before # Patched Version: unpatched # Category: Web App ...
Jorani Leave Management System version 065 suffers from a remote SQL injection vulnerability ...