vendor:
SLIMS
by:
nu11secur1ty
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: SLIMS
Affected Version From: 9.5.2000
Affected Version To: 9.5.2000
Patch Exists:
Related CWE:
CPE: a:slims.web.id:slims:9.5.0
Platforms Tested:
2022
Senayan Library Management System v9.5.0 – SQL Injection
The `keywords` parameter appears to be vulnerable to SQL injection attacks. A single quote was submitted in the keywords parameter, and a general error message was returned. Two single quotes were then submitted and the error message disappeared. The injection is confirmed manually from nu11secur1ty. The attacker can retrieve all information from the database of this system, by using this vulnerability.
Mitigation:
Input validation and sanitization should be done to prevent SQL injection attacks.