Description
RimbaLinux AhadPOS 1.11 contains a SQL injection vulnerability in the 'alamatCustomer' parameter that allows attackers to manipulate database queries through crafted POST requests. Attackers can exploit time-based and boolean-based blind SQL injection techniques to extract information or potentially interact with the underlying database.
Problem types
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Credits
Cakes
References
www.exploit-db.com/exploits/47585 (ExploitDB-47585)
github.com/rimbalinux/AhadPOS (Vendor Homepage)
www.vulncheck.com/...ux-ahadpos-alamatcustomer-sql-injection (VulnCheck Advisory: rimbalinux AhadPOS 1.11 - 'alamatCustomer' SQL Injection)