First published: Tue Sep 13 2022(Updated: )
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Archerydms Archery | >=1.4.0<1.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38540 is a SQL injection vulnerability in Archery v1.4.0 to v1.8.5.
The SQL injection vulnerability occurs via the ThreadIDs parameter in the create_kill_session interface of Archery v1.4.0 to v1.8.5.
CVE-2022-38540 has a severity rating of 9.8 (critical).
Archery versions 1.4.0 to 1.8.5 are affected by the SQL injection vulnerability.
Yes, it is recommended to update Archery to version 1.9.0 or higher to fix the SQL injection vulnerability.