CVE-2022-21666
Versions prior to Pb2.4Bfx3 allowed Sql injection in usersearch.php only for users with administrative privileges.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.19%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Useful Simple Open-Source CMS (USOC) is a content management system (CMS) for programmers. Versions prior to Pb2.4Bfx3 allowed Sql injection in usersearch.php only for users with administrative privileges. Users should replace the file `admin/pages/useredit.php` with a newer version. USOC version Pb2.4Bfx3 contains a fixed version of `admin/pages/useredit.php`.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.19% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- useful simple open-source cms project/useful simple open-source cms
- Source
- security-advisories@github.com
References
- https://github.com/Aaron-Junker/USOC/commit/c331d26aaab41a7e9e8c1c1a990132dca9d01e10Patch, Third Party Advisory
- https://github.com/Aaron-Junker/USOC/releases/tag/Pb2.4Bfx3Release Notes, Third Party Advisory
- https://github.com/Aaron-Junker/USOC/security/advisories/GHSA-557p-hhpc-4wrxThird Party Advisory
- https://github.com/Aaron-Junker/USOC/commit/c331d26aaab41a7e9e8c1c1a990132dca9d01e10Patch, Third Party Advisory
- https://github.com/Aaron-Junker/USOC/releases/tag/Pb2.4Bfx3Release Notes, Third Party Advisory
- https://github.com/Aaron-Junker/USOC/security/advisories/GHSA-557p-hhpc-4wrxThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.