header-logo
Suggest Exploit
vendor:
Curfew e-Pass Management System
by:
Puja Dey
6.1
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Curfew e-Pass Management System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: cpe: /a:curfew_e-pass_management_system:curfew_e-pass_management_system:1.0
Metasploit:
Other Scripts:
Platforms Tested: Windows 10/Wamp
2023

Curfew e-Pass Management System 1.0 – FromDate SQL Injection

The Curfew e-Pass Management System 1.0 is vulnerable to SQL Injection in the 'FromDate' parameter. By manipulating the 'FromDate' parameter, an attacker can execute arbitrary SQL queries, potentially leading to unauthorized access to the database. This vulnerability has been tested on Windows 10/Wamp.

Mitigation:

To mitigate this vulnerability, input validation and parameterized queries should be implemented to sanitize user input and prevent SQL Injection attacks.
Source

Exploit-DB raw data: