CVE-2022-27985: SQL Injection
Published Apr 26, 2022
·Updated
CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
Affected Software
1 affected component
CuppaCMS CuppaCMS=1.0
Event History
Apr 26, 2022
CVE Published
via MITRE·01:58 PM
Data Sourced
via MITRE·01:58 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-27985?
CVE-2022-27985 is considered a critical SQL injection vulnerability that can be exploited to compromise the database of CuppaCMS.
2
How do I fix CVE-2022-27985?
To fix CVE-2022-27985, you should update CuppaCMS to the latest version that addresses this SQL injection vulnerability.
3
What versions of CuppaCMS are affected by CVE-2022-27985?
CVE-2022-27985 specifically affects CuppaCMS version 1.0.
4
What types of attacks can CVE-2022-27985 enable?
CVE-2022-27985 can enable attackers to execute arbitrary SQL commands, leading to data leakage, data manipulation, or database takeover.
5
Is there a way to mitigate the impact of CVE-2022-27985 if I cannot update immediately?
If an immediate update is not possible, consider implementing web application firewall rules to help filter out malicious SQL injection attempts targeting CVE-2022-27985.