First published: Mon May 23 2022(Updated: )
Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Inoutscripts Blockchain Altexchanger | =1.2.1 | |
Nesote Inout Blockchain FiatExchanger | =2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31487 has a high severity level due to its potential for SQL injection attacks that can lead to data compromise.
To fix CVE-2022-31487, upgrade to a patched version of Inout Blockchain AltExchanger or Inout Blockchain FiatExchanger as recommended by the vendor.
CVE-2022-31487 affects Inout Blockchain AltExchanger version 1.2.1 and Inout Blockchain FiatExchanger version 2.2.1.
CVE-2022-31487 can be exploited through SQL injection, allowing attackers to manipulate database queries.
You can determine if your system is vulnerable to CVE-2022-31487 by checking if you are using the affected versions and evaluating your code for SQL injection points.