CVE-2022-24691
18.07.2022, 13:15
An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A SQL Injection vulnerability allows authenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based.
Vendor | Product | Version |
---|---|---|
dsk | dsknet | 2.16.136.0 |
dsk | dsknet | 2.17.136.5 |
𝑥
= Vulnerable software versions