CVE-2020-22669: SQL Injection
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-22669.
What is the severity of CVE-2020-22669?
The severity of CVE-2020-22669 is critical with a severity value of 9.8.
What is the affected software for CVE-2020-22669?
The affected software for CVE-2020-22669 is Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) and Debian Linux 10.0.
How does CVE-2020-22669 work?
CVE-2020-22669 allows attackers to use comment characters and variable assignments in SQL syntax to bypass Modsecurity WAF protection and perform SQL injection attacks on web applications.
Are there any available references for CVE-2020-22669?
Yes, you can find more information about CVE-2020-22669 in the following references: [link1], [link2], [link3].