PT-2022-20193 · Red Os · Red Os

Nelson Fernandes

·

Published

2022-10-31

·

Updated

2023-10-25

·

CVE-2022-3059

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned.
Description The issue allows for SQL injection, both authenticated and unauthenticated, through a vulnerable parameter. This parameter can be used to craft and inject complex SQL commands due to stacked query support. Additionally, a sleep-based inferential SQL injection technique can be employed to extract data from the database.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-3059

Affected Products

Red Os