PT-2026-2368 · Unknown · Viaviweb Wallpaper Admin

[Edd13Mora]

·

Published

2026-01-13

·

Updated

2026-01-14

·

CVE-2022-50892

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VIAVIWEB Wallpaper Admin version 1.0
Description The software contains a SQL injection issue that allows attackers to bypass authentication. Attackers can manipulate login credentials, specifically by injecting a payload such as 'admin' or 1=1-- - into the login page to gain unauthorized access to the administrative interface. The vulnerable login page is susceptible to SQL injection attacks through manipulation of login credentials. The login page is the entry point for this issue. The vulnerable parameters include the username and password fields.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-50892

Affected Products

Viaviweb Wallpaper Admin