VulnerabilityModified
CVE-2022-21643
In affected versions USOC allows for SQL injection via register.php.
CRITICAL 9.8EPSS 1.20%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.php. In particular usernames, email addresses, and passwords provided by the user were not sanitized and were used directly to construct a sql statement. Users are advised to upgrade as soon as possible. There are not workarounds for this issue.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- useful simple open-source cms project/useful simple open-source cms
- Source
- security-advisories@github.com
References
- https://github.com/Aaron-Junker/USOC/commit/21e8bfd7a9ab0b7f9344a7a3a7c32a7cdd5a0b69Patch, Third Party Advisory
- https://github.com/Aaron-Junker/USOC/security/advisories/GHSA-fjp4-phjh-jgmcThird Party Advisory
- https://github.com/Aaron-Junker/USOC/commit/21e8bfd7a9ab0b7f9344a7a3a7c32a7cdd5a0b69Patch, Third Party Advisory
- https://github.com/Aaron-Junker/USOC/security/advisories/GHSA-fjp4-phjh-jgmcThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.