← Back

CVE-2022-44015

nvd nist
Published: Dec 25, 2022Modified: Apr 15, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary commands on the MSSQL server via the xp_cmdshell extended procedure.

Affected (1)

1 product
Lieferantenmanager
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.6

Timeline

No history available yet.