Feb. 19, 2023, 9:15 a.m. |

National Vulnerability Database web.nvd.nist.gov

A vulnerability, which was classified as critical, was found in SourceCodester Simple Customer Relationship Management System 1.0. This affects an unknown part of the file /php-scrm/login.php. The manipulation of the argument Password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221493 was assigned to this vulnerability.

argument attack classified critical customer customer relationship management cve exploit file injection login management manipulation may password php public relationship scrm simple sql sql injection system vulnerability

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Sr. Application Security Engineer

@ CyberCube | Tallinn

Security Incident Response Analyst

@ Oracle | KITCHENER, ON, Canada

Senior Security Engineer

@ Minitab | Americas Remote