CVE-2022-48598

A SQL injection vulnerability exists in the reporter events type date feature of the ScienceLogic SL1 that takes unsanitized usercontrolled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
OS Command Injection
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SecuriferaCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---