Lucene search

K
cve[email protected]CVE-2022-36276
HistoryOct 04, 2023 - 4:15 p.m.

CVE-2022-36276

2023-10-0416:15:10
CWE-89
web.nvd.nist.gov
21
cve-2022-36276
tcman gim
sql injection
vulnerability
remote attacker
database

9.9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

9.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.2%

TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the ‘SqlWhere’ parameter inside the function ‘BuscarESM’. The exploitation of this vulnerability might allow a remote attacker to directly interact with the database.

Affected configurations

Vulners
NVD
Node
tcmangimRangev8.0.1
VendorProductVersionCPE
tcmangim*cpe:2.3:a:tcman:gim:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "GIM",
    "vendor": "TCMAN",
    "versions": [
      {
        "status": "affected",
        "version": "v8.0.1"
      }
    ]
  }
]

9.9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L

9.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

25.2%

Related for CVE-2022-36276