CVE-2022-40032

CRITICAL NUCLEI

Simple Task Managing System 1.0 - SQL Injection via login.php Username and Password Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2022-40032. PoCs published by Hamdi Sevben, h4md153v63n. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated SQL injection vulnerability in Simple Task Managing System v1.0 via the 'login' and 'password' parameters in loginValidation.php. It includes SQLmap commands and manual payloads to extract database information.

Description

SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Hamdi Sevben · textwebappsphp
https://www.exploit-db.com/exploits/51273

This exploit demonstrates an unauthenticated SQL injection vulnerability in Simple Task Managing System v1.0 via the 'login' and 'password' parameters in loginValidation.php. It includes SQLmap commands and manual payloads to extract database information.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Simple Task Managing System v1.0
No auth needed
Prerequisites: Access to the login page · SQLmap or similar tool for automated exploitation
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 5 stars
by h4md153v63n · poc
https://github.com/h4md153v63n/CVE-2022-40032_Simple-Task-Managing-System-V1.0-SQL-Injection-Vulnerability-Unauthenticated

This repository provides a detailed technical analysis of CVE-2022-40032, an unauthenticated SQL injection vulnerability in Simple Task Managing System 1.0. It includes SQLmap commands, example payloads, and Burp Suite requests demonstrating exploitation via the 'login' and 'password' parameters.

Classification
Writeup 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Simple Task Managing System 1.0
No auth needed
Prerequisites: Access to the login page of the vulnerable application · SQLmap or similar tool for automated exploitation
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Nuclei Templates (1)

Simple Task Managing System v1.0 - SQL Injection
CRITICALVERIFIEDby r3Y3r53

Scores

CVSS v3 9.8
EPSS 0.2069
EPSS Percentile 97.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
simple_task_managing_system_project/simple_task_managing_system 1.0
Published Feb 17, 2023
Tracked Since Feb 18, 2026