peter bassill · operator
$ cve CVE-2022-27927 JSON

CVE-2022-27927

9.8
CRITICAL · CVSS 3.1 · EPSS 13.8% (pctl 96)

Patch early

EPSS 13.8% — above the 10% action threshold.

Description

A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL database through the vulnerable course_code and/or customer_number parameter.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS13.83% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploitnone known
Published2022-04-19
Last modified2026-06-17

Affected (1)

VendorProduct
microfinance management system projectmicrofinance management system

References

→ the Explorer  ·  watch your stack  ·  NVD