vendor:
Interview Management System
by:
Saeed Bala Ahmed (r0b0tG4nG)
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Interview Management System
Affected Version From: Version 1
Affected Version To: Version 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Parrot OS
2020
Interview Management System 1.0 – ‘id’ SQL Injection
The Interview Management System 1.0 is vulnerable to SQL Injection through the 'id' parameter. An attacker can exploit this vulnerability to perform various attacks such as information disclosure of all database contents.
Mitigation:
The vendor has not released a patch for this vulnerability. It is recommended to avoid using this software or apply strict input validation to prevent SQL Injection attacks.