ZeroHour

CVE-2022-44015

PoC
CVSS 3.1
9.8 critical
EPSS
1%p66
Published
()
Modified
Description

An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary commands on the MSSQL server via the xp_cmdshell extended procedure.

Vendors
simmeth
Products
lieferantenmanager
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.