Skip to content

[FALSE-NEGATIVE] CVE-2022-31181 #13938

@mastercho

Description

@mastercho

Template IDs or paths

- CVE-2022-31181

Environment

- OS: Ubuntu 24.04
- Nuclei: v3.5.1
- Go: go1.25.3

Steps To Reproduce

nuclei -id CVE-2022-31181 -u https://site.com/ -debug

Relevant dumped responses

Anything else?

The SQL injection requires a product to be present in the wishlist to trigger successfully. However, the current template creates a new account with an empty wishlist, which prevents the injection from executing even if the vulnerability exists. This results in a false negative.

Metadata

Metadata

Assignees

Labels

false-negativeNuclei template missing valid results

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions