NVD disclosure day

Published threat advisories for March 17, 2022

CVE advisoryCRITICAL

CVE-2021-44088

Sourcecodester Attendance and Payroll System SQL Injection Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An SQL injection vulnerability in the Sourcecodester Attendance and Payroll System allows remote attackers to bypass authentication by exploiting unsanitized login parameters. This could lead to unauthorized access to sensitive data or system functions.

CVE advisoryCRITICAL

CVE-2021-44087

Sourcecodester Attendance and Payroll System RCE via Photo Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Sourcecodester Attendance and Payroll System that permits unauthenticated remote attackers to upload malicious PHP files through the photo upload feature, potentially leading to remote code execution and system compromise.

CVE advisoryKnown Exploit

CVE-2022-26501

Veeam Backup & Replication Unauthorized Access Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in Veeam Backup & Replication allows unauthorized access to internal functions, potentially leading to malicious code execution. This could impact system security and data integrity. The realistic business risk involves unauthorized access and compromise of backup data.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2022-26500

Veeam Backup & Replication Vulnerability Allows Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A flaw in Veeam Backup & Replication allows authenticated users to access internal functions, enabling attackers to upload and execute arbitrary code. This poses a risk of unauthorized system control and potential business disruption. The vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog.

• CISA KEV