{"api_version":"1","generated_at":"2026-07-23T13:16:27+00:00","cve":"CVE-2022-36030","urls":{"html":"https://cve.report/CVE-2022-36030","api":"https://cve.report/api/cve/CVE-2022-36030.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-36030","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-36030"},"summary":{"title":"CVE-2022-36030","description":"Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack of sensitization of user input. This issue has not yet been patched. Users are advised to restrict user input and to upgrade when a new release becomes available.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2022-08-20 00:15:00","updated_at":"2022-08-23 18:49:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://github.com/vinsdragonis/Project-Nexus/security/advisories/GHSA-3pv7-25cc-mjvv","name":"https://github.com/vinsdragonis/Project-Nexus/security/advisories/GHSA-3pv7-25cc-mjvv","refsource":"CONFIRM","tags":[],"title":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') and Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') and Improper Neutralization of Special Elements in Data Query Logic in api/routes/posts.js · Advisory · vinsdragonis/Project-Nexus · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-36030","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36030","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"36030","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"project-nexus_project","cpe5":"project-nexus","cpe6":"1.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2022-36030","STATE":"PUBLIC","TITLE":"SQL Injection in Project-nexus"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Project-Nexus","version":{"version_data":[{"version_value":"<= 1.0.1"}]}}]},"vendor_name":"vinsdragonis"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Project-nexus is a general-purpose blog website framework. Affected versions are subject to SQL injection due to a lack of sensitization of user input. This issue has not yet been patched. Users are advised to restrict user input and to upgrade when a new release becomes available."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}]}]},"references":{"reference_data":[{"name":"https://github.com/vinsdragonis/Project-Nexus/security/advisories/GHSA-3pv7-25cc-mjvv","refsource":"CONFIRM","url":"https://github.com/vinsdragonis/Project-Nexus/security/advisories/GHSA-3pv7-25cc-mjvv"}]},"source":{"advisory":"GHSA-3pv7-25cc-mjvv","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2022-08-20 00:15:00","lastModifiedDate":"2022-08-23 18:49:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:project-nexus_project:project-nexus:1.0.1:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}