vendor:
Zoo Management System
by:
Zeyad Azima
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Zoo Management System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: phpgurukul:zoo_management_system:1.0
Platforms Tested: Windows
2021
Zoo Management System 1.0 – ‘anid’ SQL Injection
The Zoo Management System 1.0 is vulnerable to an SQL injection in the 'anid' parameter. By adding a specific payload to the URL, an attacker can manipulate the SQL query to perform unauthorized actions. This exploit has been tested on Windows.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability. Users are advised to avoid using the affected version of the software or apply security measures such as input validation and parameterized queries to prevent SQL injection attacks.