PT-2022-27729 · Unknown · Helmet Store Showroom

Yuyudhn

·

Published

2022-12-14

·

Updated

2023-01-30

·

CVE-2022-46071

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Helmet Store Showroom version 1.0
Description The issue is related to a SQL Injection vulnerability at the Login Page. This vulnerability can be exploited to bypass admin access.
Recommendations For Helmet Store Showroom version 1.0, consider temporarily restricting access to the Login Page until a patch is available. As a mitigation measure, avoid using user input directly in SQL queries to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-46071

Affected Products

Helmet Store Showroom