Record summary

CVE-2022-46443 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

mesinkasir Bangresto 1.0 is vulnberable to SQL Injection via the itemqty%5B%5D parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryHIGHBangresto - SQL InjectionCVSS 8.8

Bangresto 1.0 is vulnberable to SQL Injection via the itemqty%5B%5D parameter.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire application and underlying database.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-89
AuthorsHarsh
Template tagscvecve2022bangrestosqlibangresto_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:bangresto_project:bangresto:1.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3