PT-2022-23708 · Unknown · Oroplatform

Published

2022-09-30

·

Updated

2024-09-16

·

CVE-2022-36961

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Orion Platform (affected versions not specified)
Description The issue concerns a vulnerable component of the Orion Platform that is susceptible to SQL Injection. An authenticated attacker could exploit this for privilege escalation or remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-36961
ZDI-22-1325

Affected Products

Oroplatform