← Back to browse · API

CVE-2022-46887

Severity
CRITICAL
CVSS
9.8
EPSS
0.19374
Risk score
45.98
CISA KEV
No
PoC
No
Published
2023-01-19
Modified
2025-04-03
First seen
2026-08-07
Aliases
EUVD-2022-49667, GHSA-G8HG-35M6-52VG
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-49667

Description

Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php.

References