CVE-2022-28080
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 57%
from disclosure to weapon0 days
Published on NVDMay 5
1st PoCMar 30
exploitation probability
57%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/50934unverifiedgithubgithub.com/erengozaydin/Royal-Event-Management-System-todate-SQL-Injection-Authenticated★ 0cve_referencepacketstormsecurity.com/files/167123/Royal-Event-Management-System-1.0-SQL-Injection.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/167123/Royal-Event-Management-System-1.0-SQL-Injection.htmlhttps://github.com/erengozaydin/Royal-Event-Management-System-todate-SQL-Injection-Authenticatedhttps://www.sourcecodester.com/php/15238/event-management-system-project-php-source-code.htmlhttps://www.sourcecodester.com/sites/default/files/download/oretnom23/Royal%20Event.zip