CVE-2022-4259
04.05.2023, 11:15
Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.
| Vendor | Product | Version |
|---|---|---|
| nozominetworks | cmc | 𝑥 < 22.5.2 |
| nozominetworks | guardian | 𝑥 < 22.5.2 |
| nozominetworks | cmc | 𝑥 < 22.5.2 |
| nozominetworks | guardian | 𝑥 < 22.5.2 |
𝑥
= Vulnerable software versions