CVE-2022-32028
Car Rental Management System 1.0 - SQL Injection
Record summary
CVE-2022-32028 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHCar Rental Management System 1.0 - SQL InjectionCVSS 7.2
Car Rental Management System 1.0 contains an SQL injection vulnerability via /admin/manage_user.php?id=. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
Source: ProjectDiscovery