CVE-2022-29007

CRITICAL EXPLOITED NUCLEI

Dairy Farm Shop Management System v1.0 - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.

Exploits (2)

exploitdb WORKING POC
by Sanjay Singh · textwebappsphp
https://www.exploit-db.com/exploits/50365
nomisec STUB
by sudoninja-noob · poc
https://github.com/sudoninja-noob/CVE-2022-29007

Nuclei Templates (1)

Dairy Farm Shop Management System 1.0 - SQL Injection
CRITICALVERIFIEDby TenBird

Scores

CVSS v3 9.8
EPSS 0.9250
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-11-13
CWE
CWE-89
Status published
Products (1)
phpgurukul/dairy_farm_shop_management_system 1.0
Published May 11, 2022
Tracked Since Feb 18, 2026