CVE-2022-29006
CRITICAL NUCLEIDirectory Management System v1.0 - SQL Injection
Title source: llmDescription
Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Directory Management System v1.0 allows attackers to bypass authentication.
Exploits (2)
Nuclei Templates (1)
Directory Management System 1.0 - SQL Injection
CRITICALVERIFIEDby TenBird
Scores
CVSS v3
9.8
EPSS
0.8595
EPSS Percentile
99.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-89
Status
published
Affected Products (1)
phpgurukul/directory_management_system
Timeline
Published
May 11, 2022
Tracked Since
Feb 18, 2026