CVE-2022-30335

Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component.
Configurations

Configuration 1

cpe:2.3:a:wealth:bonanza_wealth_management_system:7.3.2:*:*:*:*:*:*:*

Information

Published : 2022-05-09 07:15

Updated : 2022-05-17 07:15


NVD link : CVE-2022-30335

Mitre link : CVE-2022-30335

Products Affected
No products.
CWE