CVE-2022-37333: SQL Injection
SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows remote authenticated attackers to execute arbitrary SQL commands.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-37333?
CVE-2022-37333 is a SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) that allows remote authenticated attackers to execute arbitrary SQL commands.
How severe is CVE-2022-37333?
CVE-2022-37333 has a severity score of 8.8 (High).
Which software versions are affected by CVE-2022-37333?
Exment versions v5.0.2 and earlier (PHP8) and v4.4.2 and earlier (PHP7), as well as Laravel-admin versions v3.0.0 and earlier (PHP8) and v2.2.2 and earlier (PHP7), are affected by CVE-2022-37333.
How can remote authenticated attackers exploit CVE-2022-37333?
Remote authenticated attackers can exploit CVE-2022-37333 to execute arbitrary SQL commands.
Are there any references or additional resources for CVE-2022-37333?
For more information about CVE-2022-37333, you can refer to the documentation and release notes on the Exment website (https://exment.net/docs/#/release_note?id=v503-20220817) and the vulnerability report on the JVN website (https://jvn.jp/en/jp/JVN46239102/index.html).