PT-2022-24447 · Archery · Archery

Bit-Sec

·

Published

2022-09-13

·

Updated

2022-11-07

·

CVE-2022-38541

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Archery versions 1.8.3 through 1.8.5
Description The issue is related to multiple SQL injection vulnerabilities. These vulnerabilities can be exploited via the start time and stop time parameters in the my2sql interface.
Recommendations For versions 1.8.3 through 1.8.5, consider restricting access to the my2sql interface until a patch is available. As a temporary workaround, avoid using the start time and stop time parameters in the my2sql interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-38541

Affected Products

Archery