Record summary

CVE-2022-28079 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.

Description

College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 13, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Repository PoCs
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

2

Catalogued exploits

ExploitDBCollege Management System 1.0 - 'course_code' SQL Injection (Authenticated)ExploitDB exploitby Eren GozaydinNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHuberengozaydin/College-Management-System-course_code-SQL-Injection-AuthenticatedRepository PoCby erengozaydinStars: 0Not analyzed1 file

1.6 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHCollege Management System 1.0 - SQL InjectionCVSS 8.8

College Management System 1.0 contains a SQL injection vulnerability via the course code parameter.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential manipulation of the database.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-89
Authorsritikchaddha
Template tagscvecve2022sqlicmscollegemanagementcollege_management_system_projectvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:college_management_system_project:college_management_system:1.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5