← volver
CVE-2022-21643

SQL Injection in USOC

CVSS 10 CRITICALEPSS 1.2%CWE-89
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 10EPSS 1.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
04 ene 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.php. In particular usernames, email addresses, and passwords provided by the user were not sanitized and were used directly to construct a sql statement. Users are advised to upgrade as soon as possible. There are not workarounds for this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Productos afectados
Aaron-Junker · USOC