First published: Mon Oct 31 2022(Updated: )
The application was vulnerable to multiple instances of SQL injection (authenticated and unauthenticated) through a vulnerable parameter. Due to the stacked query support, complex SQL commands could be crafted and injected into the vulnerable parameter and using a sleep based inferential SQL injection it was possible to extract data from the database.
Credit: vdp@themissinglink.com.au
Affected Software | Affected Version | How to fix |
---|---|---|
Schoolbox | =21.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3059 is classified as a high severity vulnerability due to the potential for SQL injection exploits.
To fix CVE-2022-3059, update your Schoolbox application to version 21.0.3 or later where the vulnerability is patched.
CVE-2022-3059 involves both authenticated and unauthenticated SQL injection through a vulnerable parameter.
An attacker could execute complex SQL commands in the database, potentially leading to data leakage or corruption.
Yes, CVE-2022-3059 specifically affects Schoolbox version 21.0.2.