CVE-2022-29009

CRITICAL NUCLEI

Cyber Cafe Management System Project v1.0 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2022-29009. PoCs published by Sanjay Singh, sudoninja-noob. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates an SQL injection authentication bypass in Cyber Cafe Management System 1.0. By manipulating the username parameter with a SQL payload, an attacker can bypass authentication and log in as admin.

Description

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.

Exploits (2)

exploitdb WORKING POC
by Sanjay Singh · textwebappsphp
https://www.exploit-db.com/exploits/50355

This exploit demonstrates an SQL injection authentication bypass in Cyber Cafe Management System 1.0. By manipulating the username parameter with a SQL payload, an attacker can bypass authentication and log in as admin.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Cyber Cafe Management System 1.0
No auth needed
Prerequisites: Access to the login page of the target application · Ability to intercept and modify HTTP requests (e.g., using Burp Suite)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec STUB
by sudoninja-noob · poc
https://github.com/sudoninja-noob/CVE-2022-29009

The repository contains only a README.md file with a CVE identifier and no exploit code or technical details. It appears to be a placeholder or incomplete submission.

Classification
Stub 10%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Cyber Cafe Management System 1.0 - SQL Injection
CRITICALVERIFIEDby TenBird

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/50355

Scores

CVSS v3 9.8
EPSS 0.2128
EPSS Percentile 97.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
phpgurukul/cyber_cafe_management_system 1.0
Published May 11, 2022
Tracked Since Feb 18, 2026