CVE-2022-35156
Critical · CVSS 9.8Bus Pass Management System — SQL Injection
- CVSS
- 9.8
- nvd
- EPSS
- 1.27%
- 66th pct
- KEV
- No
- Class
- other
- CWE-89, CWE-89
Description
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..
Search profile — drives PoC discovery
Symbols searchdata/buspassms/download-pass.phpsearchdata parameter
Keywords CVE-2022-35156Bus Pass Management System 1.0 SQL Injectionsearchdata SQLidownload-pass.php SQL injectionbuspassms SQLiphpgurukul Bus Pass SQL injection
Versions: 1.0
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z