Security Vulnerabilities
- CVEs Published In April 2022
Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter.
Insurance Management System 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
Online Student Admission v1.0 was discovered to contain a SQL injection vulnerability via the txtapplicationID parameter.
Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables. In pinot installations that allow open access to the controller a specially crafted request can potentially be exploited to cause disruption in pinot service. Pinot release 0.10.0 fixes this. See https://docs.pinot.apache.org/basics/releases/0.10.0
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability