CVE-2022-48598

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Aug 9, 2023
Updated: Nov 7, 2023
CWE ID 78
CWE ID 89

Summary

CVE-2022-48598 is a SQL injection vulnerability affecting the "reporter events type date" feature in ScienceLogic SL1. This issue arises due to the application's failure to sanitize user-controlled input, enabling attackers to inject malicious SQL code before the query is executed against the database, potentially resulting in unauthorized access, data theft, or system compromise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share