CVE-2022-3973 | Pingkon HMS-PHP Data Pump Metadata /admin/admin.php uname/pass sql injection (EUVD-2022-43304)
A vulnerability identified as critical has been detected in Pingkon HMS-PHP. This affects an unknown function of the file /admin/admin.php of the component Data Pump Metadata. The manipulation of the argument uname/pass leads to sql injection.
This vulnerability is documented as CVE-2022-3973. The attack can be initiated remotely. Additionally, an exploit exists.