CVE-2022-38492

An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes the vulnerability.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.7 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
mitreCNA
7.7 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AC:L/AV:N/A:N/C:H/I:N/PR:L/S:C/UI:N
CVEADP
---
---
CISA-ADPADP
---
---