Daily Expense Manager SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in Daily Expense Manager version 1.0. This vulnerability allows attackers to retrieve, create, update, and delete database entries through the pname, pprice, and id parameters in the /update.php file.

Impact

Exploitation of this vulnerability allows for unauthorized database manipulation, including retrieval, creation, updating, and deletion of database records.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.