#VU63201 SQL injection in Royal Event Management System - CVE-2022-28080
Published: May 16, 2022 / Updated: May 16, 2022
Royal Event Management System
sourcecodester
Description
The vulnerability allows a remote user to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via the todate parameter. A remote user can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
Remediation
External links
- https://github.com/erengozaydin/Royal-Event-Management-System-todate-SQL-Injection-Authenticated
- https://www.sourcecodester.com/php/15238/event-management-system-project-php-source-code.html
- https://www.sourcecodester.com/sites/default/files/download/oretnom23/Royal%20Event.zip
- http://packetstormsecurity.com/files/167123/Royal-Event-Management-System-1.0-SQL-Injection.html