Description


A vulnerability classified as critical has been found in Pingkon HMS-PHP. Affected is an unknown function of the file /admin/admin.php of the component Data Pump Metadata. The manipulation of the argument uname/pass leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-213552.

Related CPE's


References


https://github.com/Pingkon/HMS-PHP/issues/1

ExploitIssue TrackingThird Party Advisory

https://vuldb.com/?id.213552

Third Party Advisory

Weaknesses



CWE-707

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 · Critical

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-11-13T10:15:10.227

2 years ago

Last modified

2023-11-07T03:52:03.047

1 year ago