cvedb.io
CVE-2022-3495
HIGH · CVSS 7.3
EPSS exploitation probability: 0%
Published 2022-10-14T07:15:09.180 · Last modified 2026-06-17T04:59:38.247

Summary

A vulnerability has been found in SourceCodester Simple Online Public Access Catalog 1.0 and classified as critical. This vulnerability affects unknown code of the file /opac/Actions.php?a=login of the component Admin Login. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-210784.

Affected products

simple_online_public_access_catalog_project — simple_online_public_access_catalog

Does this affect you?

Add your gear to cvedb and we'll alert you only when simple_online_public_access_catalog_project ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.