CVE-2022-34909

EUVD-2022-37813
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It allows SQL Injection, by which an attacker can bypass authentication and retrieve data that is stored in the database.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.7 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
mitreCNA
7.7 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AC:L/AV:L/A:N/C:H/I:H/PR:N/S:U/UI:N