CVE-2022-48593

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Aug 9, 2023
Updated: Nov 7, 2023
CWE ID 78
CWE ID 89

Summary

CVE-2022-48593 is a SQL injection vulnerability in the "topology data service" feature of ScienceLogic SL1. This vulnerability allows for the injection of arbitrary SQL code by exploiting unsanitized user-controlled input, which is then executed against the database. The affected product is ScienceLogic SL1. To remediate this vulnerability, it is recommended to apply the latest security patches and updates provided by ScienceLogic. This vulnerability poses a high risk to organizations as it can lead to unauthorized access, data loss or manipulation, and potential compromise of sensitive information.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share