Record summary

CVE-2022-32025 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id=.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHCar Rental Management System 1.0 - SQL InjectionCVSS 7.2

Car Rental Management System 1.0 contains an SQL injection vulnerability via /admin/view_car.php?id=. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-89
Authorsarafatansari
Template tagscvecve2022carrentalcmssqliauthenticatedcar_rental_management_system_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:car_rental_management_system_project:car_rental_management_system:1.0:*:*:*:*:*:*:*
Shodan: http.html:"Car Rental Management System"
Shodan: http.html:"car rental management system"
FOFA: body="car rental management system"

Source: ProjectDiscovery

References

2