漏洞描述
SQL injection occurs when a web application doesn't properly validate or sanitize user input that is used in SQL queries. Attackers can exploit this by injecting malicious SQL code into the input fields of a web application, tricking the application into executing unintended database queries.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.sourcecodester.comhttps://www.sourcecodester.com/php/15624/simple-task-managing-system-php-mysqli-free-source-code.html↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-40032↗packetstormsecurity.comhttp://packetstormsecurity.com/files/171739/Simple-Task-Managing-System-1.0-SQL-Injection.html↗www.sourcecodester.comhttps://www.sourcecodester.com/sites/default/files/download/razormist/Task%20Managing%20System%20in%20PHP.zip↗