vendor:
Complaint Management System
by:
Daniel Ortiz
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Complaint Management System
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:sourcecodester:complaint_management_system:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: XAMPP Version 5.6.40 / Windows 10
2020
Complaint Management System 1.0 – ‘username’ SQL Injection
An SQL injection vulnerability exists in Complaint Management System 1.0, which allows an attacker to inject arbitrary SQL commands via the 'username' parameter. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code in the 'username' parameter, in order to bypass authentication or retrieve sensitive data from the database.
Mitigation:
Input validation should be used to prevent SQL injection attacks. All user-supplied input should be validated and filtered before being used in SQL queries.