PT-2022-24886 · Ree6 · Ree6

Dxssucuk

·

Published

2022-10-13

·

Updated

2022-10-17

·

CVE-2022-39303

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ree6 versions prior to 1.7.0
Description This issue allows manipulation of SQL queries. The estimated number of potentially affected devices is not provided. There are no reported real-world incidents where this issue was exploited. The issue is related to SQL injection risk, which is mitigated by using Java's PreparedStatements.
Recommendations For versions prior to 1.7.0, update to version 1.7.0 to resolve the issue by utilizing Java's PreparedStatements, which allow object setting without the risk of SQL injection.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-39303
GHSA-69XV-XJFW-4PV8

Affected Products

Ree6