CVE-2022-33148: SQL Injection
Published Aug 22, 2022
·Updated
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to inject SQL by manipulating the title parameter.
Affected Software
1 affected component
WWBN AVideo=11.6
Event History
Aug 22, 2022
CVE Published
via MITRE·06:29 PM
Data Sourced
via MITRE·06:29 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-33148?
CVE-2022-33148 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2022-33148?
To fix CVE-2022-33148, update WWBN AVideo to version 12.0 or later.
3
What software is affected by CVE-2022-33148?
CVE-2022-33148 affects WWBN AVideo version 11.6.
4
Can CVE-2022-33148 be exploited remotely?
Yes, CVE-2022-33148 can be exploited remotely through a specially-crafted HTTP request.
5
What types of attacks can CVE-2022-33148 enable?
CVE-2022-33148 can enable attackers to execute arbitrary SQL queries on the database.