First published: Mon Aug 22 2022(Updated: )
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the aVideoEncoder functionality which can be used to add new videos, allowing an attacker to inject SQL by manipulating the videoDownloadedLink or duration parameter.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
WWBN AVideo | =11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-33147 is rated as a medium severity SQL injection vulnerability.
To fix CVE-2022-33147, update to the latest version of WWBN AVideo that includes the necessary patches.
An attacker can execute SQL injection attacks by sending specially-crafted HTTP requests targeting the vulnerability.
CVE-2022-33147 affects WWBN AVideo version 11.6 and previous versions in the dev master branch.
The impact of CVE-2022-33147 includes potential unauthorized access to the database and manipulation of stored data.