PT-2022-24424 · Unknown · Logrocket-Oauth2-Example

Octogonz

·

Published

2022-12-14

·

Updated

2022-12-19

·

CVE-2022-38488

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions logrocket-oauth2-example versions prior to 2020-05-27
Description The issue allows SQL injection via the /auth/register API endpoint, specifically through the username parameter.
Recommendations For versions prior to 2020-05-27, as a temporary workaround, consider restricting access to the /auth/register API endpoint or sanitizing the username parameter to prevent SQL injection until a patch is available.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-38488

Affected Products

Logrocket-Oauth2-Example