CVE-2022-2067: SQL Injection in francoisjacquet/rosariosis
Published Jun 13, 2022
·Updated
SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0.
Affected Software
1 affected component
RosarioSIS RosarioSIS<9.0
Remediation
Event History
Jun 13, 2022
CVE Published
via MITRE·12:20 PM
Data Sourced
via MITRE·12:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2067?
The severity of CVE-2022-2067 is critical, with a severity value of 9.1.
2
What is the affected software for CVE-2022-2067?
The affected software for CVE-2022-2067 is Rosariosis version up to exclusive 9.0.
3
What is the CWE of CVE-2022-2067?
The CWE of CVE-2022-2067 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).
4
How can I fix CVE-2022-2067?
To fix CVE-2022-2067, you should update your Rosariosis installation to version 9.0 or newer.
5
Where can I find more information about CVE-2022-2067?
You can find more information about CVE-2022-2067 at the following links: [GitHub Commit](https://github.com/francoisjacquet/rosariosis/commit/15d5e8700d538935b5c411b2a1e25bcf7e16c47c) [Huntr Bounty](https://huntr.dev/bounties/a85a53a4-3009-4f41-ac33-8bed8bbe16a8).