Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SalonErp SQL注入漏洞
Vulnerability Description
SalonErp是Thomas Sparber个人开发者的一个沙龙管理软件。 SalonERP 3.0.1 中存在SQL注入漏洞。该漏洞允许攻击者在生成报告时使用 SQL 查询中的sql参数注入有效负载。成功发现登录管理员密码哈希后,可以对其进行解密以获得明文密码。
CVSS Information
N/A
Vulnerability Type
N/A