Lucene search

K
nvd[email protected]NVD:CVE-2022-0495
HistorySep 21, 2022 - 9:15 a.m.

CVE-2022-0495

2022-09-2109:15:09
CWE-89
web.nvd.nist.gov
1
koha
library system
sql injection
vulnerability
parantez teknoloji

CVSS3

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

EPSS

0.002

Percentile

51.5%

The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticated SQL Injection vulnerability. This has been fixed in the version 19.05.03.01.

Affected configurations

Nvd
Node
parantezteknolojikoha_library_automationRange<19.05.03.01
VendorProductVersionCPE
parantezteknolojikoha_library_automation*cpe:2.3:a:parantezteknoloji:koha_library_automation:*:*:*:*:*:*:*:*

CVSS3

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

EPSS

0.002

Percentile

51.5%

Related for NVD:CVE-2022-0495