CVE-2022-37138 The LMS 1.0 is vulnerable to SQL Injection at the login page, which allows attackers to log in as Administrator as username form.

To inject SQL Injection, attacker can send request with SQL statement in the ‘INPUT>’ tag. An attacker can send the following injection request to the login page of Loan Management System to login as Administrator. INPUT type=”hidden” value=”SQL>” ‘ INPUT type=”hidden” value=”SQL>” ‘ In the ‘INPUT>’ tag, attacker
