First published: Tue Sep 13 2022(Updated: )
Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Archerydms Archery | >=1.8.3<=1.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38541 refers to multiple SQL injection vulnerabilities found in Archery v1.8.3 to v1.8.5.
CVE-2022-38541 has a severity rating of 9.8, which is considered critical.
CVE-2022-38541 affects Archery versions 1.8.3 to 1.8.5.
The CWE ID for CVE-2022-38541 is 89.
To fix CVE-2022-38541, it is recommended to update Archery to a version beyond 1.8.5, as the SQL injection vulnerabilities have been patched in later releases.