CVE-2022-29007

CRITICAL EXPLOITED NUCLEI

Dairy Farm Shop Management System v1.0 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-29007 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Sanjay Singh, sudoninja-noob. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates an SQL injection authentication bypass in Dairy Farm Shop Management System 1.0. By manipulating the username parameter in the login request, an attacker can bypass authentication and log in as an admin without valid credentials.

Description

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows attackers to bypass authentication.

Exploits (2)

exploitdb WORKING POC
by Sanjay Singh · textwebappsphp
https://www.exploit-db.com/exploits/50365

This exploit demonstrates an SQL injection authentication bypass in Dairy Farm Shop Management System 1.0. By manipulating the username parameter in the login request, an attacker can bypass authentication and log in as an admin without valid credentials.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Dairy Farm Shop Management System v1.0
No auth needed
Prerequisites: Access to the login page of the target application · Ability to intercept and modify HTTP requests (e.g., using Burp Suite)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec STUB
by sudoninja-noob · poc
https://github.com/sudoninja-noob/CVE-2022-29007

The repository contains only a README.md file with a CVE identifier and no exploit code or technical details. It appears to be a placeholder or incomplete submission.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Dairy Farm Shop Management System 1.0 - SQL Injection
CRITICALVERIFIEDby TenBird

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/50365

Scores

CVSS v3 9.8
EPSS 0.1833
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-11-13
CWE
CWE-89
Status published
Products (1)
phpgurukul/dairy_farm_shop_management_system 1.0
Published May 11, 2022
Tracked Since Feb 18, 2026