The Microfinance Management System Project maintains a focused financial management application designed for microfinance institutions, with its disclosed vulnerability footprint centered on web-application input handling. The recurring issues reflect classic application-layer weaknesses: SQL injection and cross-site scripting flaws that arise in systems handling untrusted user input across database queries and dynamic content generation. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Microfinance Management System Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27927CRITICAL A SQL injection vulnerability exists in Microfinance Management System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL dat | Apr 19, 2022 | 9.8 | 49 | NO | YES |
CVE-2022-1083CRITICAL A vulnerability classified as critical has been found in Microfinance Management System. The manipulation of arguments like customer_type_number/account_number/account_status_numbe | Mar 29, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-1082CRITICAL A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been rated as critical. This issue affects the file /mims/login.php of the Login Page. The ma | Mar 29, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-1081MEDIUM A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been declared as problematic. This vulnerability affects the file /mims/app/addcustomerHandle | Mar 29, 2022 | 6.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Microfinance Management System Project.
Media articles that mention a CVE ID that affects a product developed by Microfinance Management System Project — matched by CVE ID, not by vendor name.