CVE-2022-4093
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.07%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In some cases, an attacker can obtain a persistent backdoor into an organization's systems, leading to a long-term compromise that can go unnoticed for an extended period. This affect 16.0.1 and 16.0.2 only. 16.0.0 or lower, and 16.0.3 or higher are not affected
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.07% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- dolibarr/dolibarr erp\/crm
- Source
- security@huntr.dev
References
- https://github.com/dolibarr/dolibarr/commit/7c1eac9774bd1fed0b7b4594159f2ac2d12a4011Patch, Third Party Advisory
- https://huntr.dev/bounties/677ca8ee-ffbc-4b39-b294-2ce81bd56788Exploit, Issue Tracking, Patch, Third Party Advisory
- https://github.com/dolibarr/dolibarr/commit/7c1eac9774bd1fed0b7b4594159f2ac2d12a4011Patch, Third Party Advisory
- https://huntr.dev/bounties/677ca8ee-ffbc-4b39-b294-2ce81bd56788Exploit, Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.