← Back to browse · API

CVE-2022-26959

Severity
CRITICAL
CVSS
10.0
EPSS
0.00803
Risk score
40.28
CISA KEV
No
PoC
No
Published
2022-09-16
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2022-31503, GHSA-R9XM-6R9G-XGP9
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-31503

Description

There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ directory and the userID parameter of the login.jsp page in the /northstar/iphone/ directory. Exploitation of the SQL injection vulnerabilities allows full access to the database which contains critical data for organization’s that make full use of the software suite.

References