packetstormsecurity.com
http://packetstormsecurity.com/files/167131/College-Management-System-1.0-SQL-Injection.html CVE-2022-28079
HIGHNuclei
college_management_system_project college_management_system Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2022-28079 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.
Description
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
college_management_systemBrowse college_management_system_project / college_management_system | VulnCheck | Version data not supplied | |
Proofs of concept
2Catalogued exploits
ExploitDBCollege Management System 1.0 - 'course_code' SQL Injection (Authenticated)ExploitDB exploitby Eren GozaydinNot analyzed1 file
Repository PoCs
GitHuberengozaydin/College-Management-System-course_code-SQL-Injection-AuthenticatedRepository PoCby erengozaydinStars: 0Not analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHCollege Management System 1.0 - SQL InjectionCVSS 8.8
College Management System 1.0 contains a SQL injection vulnerability via the course code parameter.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential manipulation of the database.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve2022sqlicmscollegemanagementcollege_management_system_projectvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:college_management_system_project:college_management_system:1.0:*:*:*:*:*:*:*
https://github.com/erengozaydin/College-Management-System-course_code-SQL-Injection-Authenticated https://download.code-projects.org/details/1c3b87e5-f6a6-46dd-9b5f-19c39667866f https://nvd.nist.gov/vuln/detail/CVE-2022-28079 https://code-projects.org/college-management-system-in-php-with-source-code/ https://www.nu11secur1ty.com/2022/05/cve-2022-28079.html
Source: ProjectDiscovery
References
5code-projects.org
https://code-projects.org/college-management-system-in-php-with-source-code github.com
https://github.com/erengozaydin/College-Management-System-course_code-SQL-Injection-Authenticated nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-28079 nu11secur1ty.com
https://www.nu11secur1ty.com/2022/05/cve-2022-28079.html