CVE-2022-35148: SQL Injection
Published Aug 17, 2022
·Updated
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.
Affected Software
13 affected components
maccms Maccms=10.0-2021.1000.1081
maccms Maccms=10.0-2022.1000.1099
maccms Maccms=10.0-2022.1000.3001
maccms Maccms=10.0-2022.1000.3002
maccms Maccms=10.0-2022.1000.3004
maccms Maccms=10.0-2022.1000.3005
maccms Maccms=10.0-2022.1000.3025
maccms Maccms=10.0-2022.1000.3026
maccms Maccms=10.0-2022.1000.3027
maccms Maccms=10.0-2022.1000.3028
maccms Maccms=10.0-2022.1000.3029
maccms Maccms=10.0-2022.1000.3030
maccms Maccms=10.0-2022.1000.3031
Remediation
Patch Available
Event History
Aug 17, 2022
CVE Published
via MITRE·08:56 PM
Data Sourced
via MITRE·08:56 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-35148.
2
What is the severity level of CVE-2022-35148?
The severity level of CVE-2022-35148 is medium with a CVSS score of 6.5.
3
How does CVE-2022-35148 impact Maccms versions 10.0-2021.1000.1081 to 10.0-2022.1000.3031?
CVE-2022-35148 allows SQL injection via the table parameter at database/columns.html in Maccms versions 10.0-2021.1000.1081 to 10.0-2022.1000.3031.
4
What is the recommended fix for CVE-2022-35148?
The recommended fix for CVE-2022-35148 is to upgrade Maccms to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2022-35148?
More information about CVE-2022-35148 can be found at the following link: [CVE-2022-35148](https://github.com/magicblack/maccms10/issues/931).