peter bassill · operator
$ cve CVE-2022-29009 JSON

CVE-2022-29009

9.8
CRITICAL · CVSS 3.1 · EPSS 22.9% (pctl 98)

Patch early

EPSS 22.9% — above the 10% action threshold.

Description

Multiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Cyber Cafe Management System Project v1.0 allows attackers to bypass authentication.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS22.91% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploitnone known
Published2022-05-11
Last modified2026-06-17

Affected (1)

VendorProduct
phpgurukulcyber cafe management system

References

→ the Explorer  ·  watch your stack  ·  NVD