Record summary

CVE-2022-46071 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALHelmet Store Showroom v1.0 - SQL InjectionCVSS 9.8

There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.

Impact

Successful exploitation of this vulnerability could allow an attacker to extract sensitive information from the database.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-89
AuthorsHarsh
Template tagscvecve2022sqliadmin-bypasshelmethelmet_store_showroom_site_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:helmet_store_showroom_site_project:helmet_store_showroom_site:1.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3