Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /purchase_order/admin/login.php.
View the template here CVE-2023-29622.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2023-29622