nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-46071 CVE-2022-46071
CRITICALNuclei
Helmet Store Showroom v1.0 - SQL Injection
Record summary
CVE-2022-46071 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2025 · Source: CVE List
Nuclei templates
1ProjectDiscoveryCRITICALHelmet Store Showroom v1.0 - SQL InjectionCVSS 9.8
There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.
Impact
Successful exploitation of this vulnerability could allow an attacker to extract sensitive information from the database.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
WeaknessesCWE-89
AuthorsHarsh
Template tagscvecve2022sqliadmin-bypasshelmethelmet_store_showroom_site_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:helmet_store_showroom_site_project:helmet_store_showroom_site:1.0:*:*:*:*:*:*:*
Source: ProjectDiscovery
References
3youtube.com
https://www.youtube.com/watch?v=5wit1Arzwxs&feature=youtu.be yuyudhn.github.io
https://yuyudhn.github.io/CVE-2022-46071