SQL injection vulnerability exists in the school information query interface (repschoolproj.php) of the EMS 6.2 system of the Office of the Thai Basic Education Commission, which can lead to data leakage.
References
Link | Resource |
---|---|
http://eme1.obec.go.th | Broken Link |
http://eme1.obec.go.th/~eme62/repschoolproj.php?claster=school&idarea=648 | Broken Link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/235480 | Third Party Advisory |
https://github.com/00xdF/emes/blob/main/readme.md | Broken Link |
Configurations
History
No history.
Information
Published : 2022-09-06 20:15
Updated : 2024-02-28 19:29
NVD link : CVE-2022-37185
Mitre link : CVE-2022-37185
CVE.ORG link : CVE-2022-37185
JSON object : View
Products Affected
ems_project
- ems
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')