CVE-2022-28080
HIGH NUCLEIRoyal Event Management System 1.0 - SQL Injection via todate Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2022-28080. PoCs published by Eren Gozaydin, erengozaydin. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an authenticated SQL injection vulnerability in Royal Event Management System 1.0 via the 'todate' parameter. The PoC includes a boolean-based payload and a Burp Suite request example, along with instructions for using SQLmap to extract database data.
Description
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
Exploits (2)
This exploit demonstrates an authenticated SQL injection vulnerability in Royal Event Management System 1.0 via the 'todate' parameter. The PoC includes a boolean-based payload and a Burp Suite request example, along with instructions for using SQLmap to extract database data.
This PoC demonstrates an authenticated SQL injection vulnerability in Royal Event Management System 1.0 via the 'todate' parameter. It includes a Burp Suite request and SQLmap usage for exploitation.
Nuclei Templates (1)
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H