CyberSec.Space Logo
CVEブラウザに戻る

CVE-2022-48603

HIGH
8.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2023-08-09
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

Affected Platforms (CPE)

📦
Sciencelogic

Sl1

<= 11.1.2

References & Advisories

関連する脆弱性情報