ZeroHour

CVE-2022-39056

CVSS 3.1
9.8 critical
EPSS
<1%p55
Published
()
Modified
Description

RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify and delete database.

Vendors
changingtec
Products
rava certificate validation system
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.