DIGIT CENTRIS ERP SQL Injection Vulnerability
Vulnerability
A SQL injection vulnerability has been identified in DIGIT CENTRIS ERP, affecting all versions. This vulnerability allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'datum1', 'datum2', 'KID', and 'PID' parameters. Attackers can send POST requests to 'korisnikinfo.php' with malicious SQL syntax in these parameters to extract or modify sensitive database information.
Impact
Exploitation of this vulnerability allows for unauthorized manipulation of database queries, potentially leading to unauthorized data access or modification.
Reproduction
To reproduce this vulnerability, send a POST request to 'korisnikinfo.php' with injected SQL code in the 'datum1', 'datum2', 'KID', and 'PID' parameters. The injected SQL can be crafted to extract or modify database information.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
