PT-2025-54232 · Unknown · Sound4 Impact+3

Published

2025-12-30

·

Updated

2025-12-31

·

CVE-2022-50694

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and earlier
Description The software contains an SQL injection issue in the username POST parameter of the ''index.php'' file. Attackers can manipulate database queries by injecting arbitrary SQL code through this parameter, potentially bypassing authentication and gaining access to unauthorized database information.
Recommendations Versions prior to 2.x should be updated. As a temporary workaround, restrict or sanitize input to the username parameter in the ''index.php'' file.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-50694

Affected Products

Sound4 Eco
Sound4 First
Sound4 Impact
Sound4 Pulse