Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T06:48:36.140Z

Reserved: 2022-05-09T00:00:00

Link: CVE-2022-30335

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-09T19:15:07.987

Modified: 2024-11-21T07:02:36.967

Link: CVE-2022-30335

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.