First published: Tue Aug 16 2022(Updated: )
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to inject SQL by manipulating the description parameter.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
WWBN AVideo | =11.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34652 is considered a critical severity vulnerability due to its potential for SQL injection.
To fix CVE-2022-34652, upgrade to a patched version of WWBN AVideo beyond 11.6 that resolves the SQL injection vulnerability.
CVE-2022-34652 specifically impacts the ObjectYPT functionality of WWBN AVideo version 11.6.
Attackers can exploit CVE-2022-34652 by sending specially-crafted HTTP requests to execute arbitrary SQL commands.
CVE-2022-34652 affects WWBN AVideo version 11.6 and the development master commit prior to a fix.