9.8
CVSSv3

CVE-2022-40347

Published: 17/02/2023 Updated: 06/04/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows malicious users to execute arbitrary code and gain sensitive information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

intern record system project intern record system 1.0

Exploits

Intern Record System version 10 suffers from a remote SQL injection vulnerability ...

Github Repositories

CVE-2022-40347: Intern Record System - 'phone', 'email', 'deptType' and 'name' SQL Injection (Unauthenticated)

CVE-2022-40347: Intern Record System - 'phone', 'email', 'deptType' and 'name' SQL Injection (Unauthenticated) Exploit Title: Intern Record System - 'phone', 'email', 'deptType' and 'name' SQL Injection (Unauthenticated) Date: 2022-06-09 Exploit Author: Hamdi Sevben Vendor Homepage: code-pr