{"api_version":"1","generated_at":"2026-07-23T11:16:31+00:00","cve":"CVE-2022-36258","urls":{"html":"https://cve.report/CVE-2022-36258","api":"https://cve.report/api/cve/CVE-2022-36258.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-36258","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-36258"},"summary":{"title":"CVE-2022-36258","description":"A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as \"searchTxt\".","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-09-12 04:15:00","updated_at":"2022-09-15 03:51:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://github.com/sazanrjb/InventoryManagementSystem","name":"https://github.com/sazanrjb/InventoryManagementSystem","refsource":"MISC","tags":[],"title":"GitHub - sazanrjb/InventoryManagementSystem: A software developed using Java SE which provides as easy way to track the products, suppliers, customers as well as purchase and sales information. It also records the stock currently available in the store.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://gist.github.com/ziyishen97/3553468b534c250f7b0d47e8a4c5fa52","name":"https://gist.github.com/ziyishen97/3553468b534c250f7b0d47e8a4c5fa52","refsource":"MISC","tags":[],"title":"Public Reference for CVE-2022-36258 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/sazanrjb/InventoryManagementSystem/issues/14","name":"https://github.com/sazanrjb/InventoryManagementSystem/issues/14","refsource":"MISC","tags":[],"title":"Sql Injection Security Issues · Issue #14 · sazanrjb/InventoryManagementSystem · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-36258","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36258","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"36258","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"inventorymanagementsystem_project","cpe5":"inventorymanagementsystem","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2022-36258","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A SQL injection vulnerability in CustomerDAO.java in sazanrjb InventoryManagementSystem 1.0 allows attackers to execute arbitrary SQL commands via the parameters such as \"searchTxt\"."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/sazanrjb/InventoryManagementSystem/issues/14","refsource":"MISC","name":"https://github.com/sazanrjb/InventoryManagementSystem/issues/14"},{"url":"https://github.com/sazanrjb/InventoryManagementSystem","refsource":"MISC","name":"https://github.com/sazanrjb/InventoryManagementSystem"},{"refsource":"MISC","name":"https://gist.github.com/ziyishen97/3553468b534c250f7b0d47e8a4c5fa52","url":"https://gist.github.com/ziyishen97/3553468b534c250f7b0d47e8a4c5fa52"}]}},"nvd":{"publishedDate":"2022-09-12 04:15:00","lastModifiedDate":"2022-09-15 03:51:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:inventorymanagementsystem_project:inventorymanagementsystem:1.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}