CVE-2022-36193
CRITICALCVSS 9.8/10EPSS 1.39%
Last modified
CVE-2022-36193 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.. EPSS estimates a 1.39% chance of exploitation in the next 30 days.
Description
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lahirudanushka | School Management System | 1.0 |
References
- https://github.com/G37SYS73M/Advisory_G37SYS73M/blob/main/CVE-2022-36193/POC.mdExploit, Third Party Advisory
- https://github.com/G37SYS73M/Advisory_G37SYS73M/blob/main/CVE-2022-36193/POC.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-36193?
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.
How severe is CVE-2022-36193?
CVE-2022-36193 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.39% probability of exploitation in the next 30 days.
How do I fix CVE-2022-36193?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-36180Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (X…9.6
- CVE-2022-36182Hashicorp Boundary v0.8.0 is vulnerable to Clickjacking whic…6.1
- CVE-2022-36186A Null Pointer dereference vulnerability exists in GPAC 2.1-…7.5
- CVE-2022-3619A vulnerability has been found in Linux Kernel and classifie…4.3
- CVE-2022-36190GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free v…9.8
- CVE-2022-36191A heap-buffer-overflow had occurred in function gf_isom_dovi…5.5
- CVE-2022-36194Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS)…5.4
- CVE-2022-36197BigTree CMS 4.4.16 was discovered to contain an arbitrary fi…5.4
- CVE-2022-36198Multiple SQL injections detected in Bus Pass Management Syst…9.8
- CVE-2022-3620A vulnerability was found in Exim and classified as problema…9.8
- CVE-2022-36200In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin…7.5
- CVE-2022-36201Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi…9.8
Are you affected by CVE-2022-36193?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
