Lucene search

K
nvd[email protected]NVD:CVE-2022-1887
HistoryDec 22, 2022 - 8:15 p.m.

CVE-2022-1887

2022-12-2220:15:13
CWE-89
web.nvd.nist.gov
1
cve-2022-1887
sql injection
firefox ios

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

51.5%

The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.

Affected configurations

NVD
Node
mozillafirefoxRange<101
AND
appleiphone_osMatch-

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

51.5%