CVE-2022-48591

A SQL injection vulnerability exists in the vendor_state parameter of the vendor print report feature of the ScienceLogic SL1 that takes unsanitized usercontrolled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
OS Command Injection
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SecuriferaCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---