Record summary

CVE-2022-32022 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?action=login.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHCar Rental Management System 1.0 - SQL InjectionCVSS 7.2

Car Rental Management System 1.0 contains an SQL injection vulnerability via /admin/ajax.php?action=login. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential manipulation of the database.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-89
Authorsarafatansari
Template tagscvecve2022carrentalcmssqlilogin-bypasscar_rental_management_system_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:car_rental_management_system_project:car_rental_management_system:1.0:*:*:*:*:*:*:*
Shodan: http.html:"Car Rental Management System"
Shodan: http.html:"car rental management system"
FOFA: body="car rental management system"

Source: ProjectDiscovery

References

3