Vulnerability Details CVE-2022-48596
A SQL injection vulnerability exists in the “ticket queue watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.8%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-48596
-
cpe:2.3:a:sciencelogic:sl1:10.1.0
-
cpe:2.3:a:sciencelogic:sl1:10.1.1
-
cpe:2.3:a:sciencelogic:sl1:10.1.2
-
cpe:2.3:a:sciencelogic:sl1:10.1.3
-
cpe:2.3:a:sciencelogic:sl1:10.1.4
-
cpe:2.3:a:sciencelogic:sl1:10.1.5
-
cpe:2.3:a:sciencelogic:sl1:10.1.6
-
cpe:2.3:a:sciencelogic:sl1:10.1.7
-
cpe:2.3:a:sciencelogic:sl1:10.1.8
-
cpe:2.3:a:sciencelogic:sl1:10.2.0
-
cpe:2.3:a:sciencelogic:sl1:10.2.1
-
cpe:2.3:a:sciencelogic:sl1:10.2.2
-
cpe:2.3:a:sciencelogic:sl1:10.2.3
-
cpe:2.3:a:sciencelogic:sl1:10.2.4
-
cpe:2.3:a:sciencelogic:sl1:10.2.4.1
-
cpe:2.3:a:sciencelogic:sl1:10.2.5
-
cpe:2.3:a:sciencelogic:sl1:10.2.6
-
cpe:2.3:a:sciencelogic:sl1:10.2.6.1
-
cpe:2.3:a:sciencelogic:sl1:10.2.7
-
cpe:2.3:a:sciencelogic:sl1:11.1.0
-
cpe:2.3:a:sciencelogic:sl1:11.1.0.1
-
cpe:2.3:a:sciencelogic:sl1:11.1.1
-
cpe:2.3:a:sciencelogic:sl1:11.1.1.2
-
cpe:2.3:a:sciencelogic:sl1:11.1.2