CVE-2022-46071

There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.
References
Link Resource
https://www.youtube.com/watch?v=5wit1Arzwxs&feature=youtu.be Exploit Third Party Advisory
https://yuyudhn.github.io/CVE-2022-46071/ Exploit Third Party Advisory
https://www.youtube.com/watch?v=5wit1Arzwxs&feature=youtu.be Exploit Third Party Advisory
https://yuyudhn.github.io/CVE-2022-46071/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:helmet_store_showroom_site_project:helmet_store_showroom_site:1.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:30

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de inyección SQL en la página de inicio de sesión de Helmet Store Showroom v1.0. Esta vulnerabilidad se puede aprovechar para evitar el acceso de administrador.
References () https://www.youtube.com/watch?v=5wit1Arzwxs&feature=youtu.be - Exploit, Third Party Advisory () https://www.youtube.com/watch?v=5wit1Arzwxs&feature=youtu.be - Exploit, Third Party Advisory
References () https://yuyudhn.github.io/CVE-2022-46071/ - Exploit, Third Party Advisory () https://yuyudhn.github.io/CVE-2022-46071/ - Exploit, Third Party Advisory

Information

Published : 2022-12-14 18:15

Updated : 2025-04-22 03:15


NVD link : CVE-2022-46071

Mitre link : CVE-2022-46071

CVE.ORG link : CVE-2022-46071


JSON object : View

Products Affected

helmet_store_showroom_site_project

  • helmet_store_showroom_site
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')