First published: Mon Aug 22 2022(Updated: )
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to inject SQL by manipulating the title parameter.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
WWBN AVideo | =11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-33148 is classified as a high-severity SQL injection vulnerability.
To fix CVE-2022-33148, update WWBN AVideo to version 12.0 or later.
CVE-2022-33148 affects WWBN AVideo version 11.6.
Yes, CVE-2022-33148 can be exploited remotely through a specially-crafted HTTP request.
CVE-2022-33148 can enable attackers to execute arbitrary SQL queries on the database.