CRITICAL
Pingkon HMS-PHP Data Pump Metadata admin.php sql injection
Published Nov 13, 2022
9.8
CRITICALCVSS 3.1
EPSS 0.61%
Description
A vulnerability classified as critical has been found in Pingkon HMS-PHP. Affected is an unknown function of the file /admin/admin.php of the component Data Pump Metadata. The manipulation of the argument uname/pass leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-213552.
Affected products
-
Affected
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43304 Advisory
- https://github.com/Pingkon/HMS-PHP/issues/1 ExploitIssue TrackingThird Party Advisory
- https://vuldb.com/?id.213552 Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-43304 | Advisory | |
| https://github.com/Pingkon/HMS-PHP/issues/1 | ExploitIssue TrackingThird Party Advisory | |
| https://vuldb.com/?id.213552 | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Nov 13, 2022
Updated Apr 14, 2025
Reserved Nov 13, 2022
Link CVE-2022-3973
CISA Vulnrichment
Updated Apr 14, 2025
Red Hat
No data
GitHub
No data