Lucene search

K
cve[email protected]CVE-2022-46763
HistoryDec 27, 2022 - 1:15 a.m.

CVE-2022-46763

2022-12-2701:15:10
CWE-89
web.nvd.nist.gov
46
cve-2022-46763
sql injection
trueconf server
arbitrary code execution
database security

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

9.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.3%

A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code.

Affected configurations

NVD
Node
microsoftwindowsMatch-
AND
trueconfserverRange<5.2.6
CPENameOperatorVersion
trueconf:servertrueconf serverlt5.2.6

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

9.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

60.3%

Related for CVE-2022-46763