CVE-2022-33147: SQL Injection
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the aVideoEncoder functionality which can be used to add new videos, allowing an attacker to inject SQL by manipulating the videoDownloadedLink or duration parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-33147?
CVE-2022-33147 is rated as a medium severity SQL injection vulnerability.
How do I fix CVE-2022-33147?
To fix CVE-2022-33147, update to the latest version of WWBN AVideo that includes the necessary patches.
What kind of attacks can be executed through CVE-2022-33147?
An attacker can execute SQL injection attacks by sending specially-crafted HTTP requests targeting the vulnerability.
Which versions of WWBN AVideo are affected by CVE-2022-33147?
CVE-2022-33147 affects WWBN AVideo version 11.6 and previous versions in the dev master branch.
What is the impact of CVE-2022-33147 on affected systems?
The impact of CVE-2022-33147 includes potential unauthorized access to the database and manipulation of stored data.