CVE-2022-35115: SQL Injection
Published Aug 23, 2022
·Updated
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.
Affected Software
1 affected component
IceWarp WebClient DC2=13.0.2.9
Event History
Aug 23, 2022
CVE Published
via MITRE·05:36 PM
Data Sourced
via MITRE·05:36 PM
Description
Frequently Asked Questions
1
What is CVE-2022-35115?
CVE-2022-35115 is a SQL injection vulnerability found in IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9).
2
How severe is CVE-2022-35115?
CVE-2022-35115 has a severity rating of 9.8 (critical).
3
Which software version is affected by CVE-2022-35115?
The software version affected by CVE-2022-35115 is IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9).
4
How can I fix CVE-2022-35115?
To fix CVE-2022-35115, update to DC2 Update 2 Build 10 (13.0.2.10) or later.
5
Where can I find more information about CVE-2022-35115?
You can find more information about CVE-2022-35115 in the IceWarp Community Post and the CVE-2022-35115.txt file.