Actor
Purchase Order Management System (POMS) version 1.0 is vulnerable to unauthenticated SQL injection via the password parameter, allowing for exfiltration or out-of-band communication via the MySQL load_file function.