Record summary

CVE-2022-28080 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.

Description

Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1
Nuclei templates
1

Proofs of concept

2

Catalogued exploits

ExploitDBRoyal Event Management System 1.0 - 'todate' SQL Injection (Authenticated)ExploitDB exploitby Eren GozaydinNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHuberengozaydin/Royal-Event-Management-System-todate-SQL-Injection-AuthenticatedRepository PoCby erengozaydinStars: 0Not analyzed1 file

1.7 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHRoyal Event - SQL InjectionCVSS 8.8

Royal Event is vulnerable to a SQL injection vulnerability.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire database.

Remediation

To remediate this vulnerability, input validation and parameterized queries should be implemented to prevent SQL Injection attacks.

WeaknessesCWE-89
Authorslucasljm2001, ekrause, ritikchaddha
Template tagscvecve2022royaleventedbsqliauthenticatedcmsintrusiveevent_management_system_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:event_management_system_project:event_management_system:1.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5