CVE-2022-29009 is a critical SQL injection vulnerability affecting the Admin panel of Cyber Cafe Management System Project v1.0, specifically through its username and password parameters. This flaw allows unauthenticated attackers to bypass authentication and gain full control over the system, leading to complete compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog or showing active exploitation, public Nuclei templates exist for detection, and its high EPSS and FAUCET scores indicate a significant risk despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:phpgurukul:cyber_cafe_management_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.