PT-2022-3808 · Mozilla+1 · Firefox+1

Muneaki Nishimura

·

Published

2022-06-01

·

Updated

2023-07-11

·

CVE-2022-1887

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Firefox for iOS versions prior to 101
Description The issue is related to a lack of protection against SQL query structure exploitation. This could allow a remote attacker to send specially crafted data to the application, potentially executing arbitrary SQL commands. The search term could be specified externally to trigger SQL injection.
Recommendations For versions prior to 101, update to version 101 or later to resolve the issue. As a temporary workaround, consider restricting access to external search terms to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-4336
ALT-PU-2023-4339
BDU:2022-04603
CVE-2022-1887

Affected Products

Alt Linux
Firefox