Description
dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access.
Problem types
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
1.0-2022
Credits
nu11secur1ty
References
www.exploit-db.com/exploits/51818 (ExploitDB-51818)
www.mayurik.com/...t-pharmacy-billing-software-free-download (Mayuri K Pharmacy Billing Software)
github.com/...ain/vendors/mayuri_k/2022/dawa-pharma-1.0-2022 (GitHub Repository for CVE-nu11secur1ty)
www.nu11secur1ty.com/ (nu11secur1ty Home Page)
www.vulncheck.com/...ma-10-sql-injection-via-email-parameter