CVE-2022-50805

HIGH

Senayan Library Management System 9.0.0 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-50805. PoCs published by nu11secur1ty.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Senayan Library Management System v9.0.0 via the 'class' parameter. The payload uses a boolean-based blind technique with MySQL's RLIKE function to confirm the vulnerability.

Description

Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parameter that allows attackers to inject malicious SQL queries. Attackers can exploit the vulnerability by submitting crafted payloads to manipulate database queries and potentially extract sensitive information.

Exploits (1)

exploitdb WORKING POC
by nu11secur1ty · textwebappsphp
https://www.exploit-db.com/exploits/51161

This exploit demonstrates a SQL injection vulnerability in Senayan Library Management System v9.0.0 via the 'class' parameter. The payload uses a boolean-based blind technique with MySQL's RLIKE function to confirm the vulnerability.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Senayan Library Management System v9.0.0
No auth needed
Prerequisites: Access to the vulnerable endpoint with the 'class' parameter
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4

Scores

CVSS v3 8.2
EPSS 0.0031
EPSS Percentile 22.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
SLIMS/Senayan Library Management System 9.0.0
Published Jan 13, 2026
Tracked Since Feb 18, 2026