CVE-2022-31346

Critical
|9.8
No Exploit

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to manipulate the online car wash booking system's database, potentially deleting services or accessing sensitive information. It requires the attacker to send a specially crafted request to a specific URL in the system.

Technical Description

Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/classes/Master.php?f=delete_service.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$13,000($5K-$15K)
Vendor Response
Grade FPatched in 1357 days

Quick Information

Published

Jun 2, 2022

over 3 years ago

Last Modified

Feb 18, 2026

2 days ago

Vendor

oretnom23

Product

online car wash booking system

Related Vulnerabilities

CVE-2023-1041Medium

This vulnerability allows an attacker to inject malicious scripts into the website, which could lead to unauthorized actions or data theft from users who visit the affected page. It can be exploited remotely by manipulating a specific input field without needing any special access or credentials.

CVE-2022-31354Critical

This vulnerability allows an attacker to manipulate the online car wash booking system's database, potentially gaining access to sensitive information or altering data. To exploit this, the attacker needs to send specially crafted requests to a specific URL in the system.

CVE-2022-31353Critical

This vulnerability allows an attacker to manipulate the database of the online car wash booking system, potentially gaining access to sensitive information or altering data. It can be exploited by sending specially crafted requests to a specific URL, making it critical for anyone using this system to secure it immediately.

CVE-2022-31352Critical

This vulnerability allows an attacker to manipulate the database of the online car wash booking system, potentially gaining access to sensitive information or altering data. It requires the attacker to send a specially crafted request to the manage_service.php page with a specific ID parameter.

CVE-2022-31351Critical

This vulnerability allows an attacker to manipulate the online car wash booking system's database by injecting harmful SQL code through a specific URL, potentially gaining access to sensitive information or altering data. To exploit this, the attacker needs to access the admin services page with the right parameters, making it critical for system security.