CVE-2022-42232: SQL Injection
Published Oct 14, 2022
·Updated
Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/classes/Master.php?f=deletestorage.
Affected Software
2 affected components
oretnom23 Simple Cold Storage Management System=1.0
Simple Cold Storage Management System Project Simple Cold Storage Management System=1.0
Event History
Oct 14, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-42232?
CVE-2022-42232 is a vulnerability found in Simple Cold Storage Management System v1.0 that allows SQL Injection attacks via the /csms/classes/Master.php?f=delete_storage endpoint.
2
How severe is CVE-2022-42232?
CVE-2022-42232 has a severity rating of 7.2, which is considered high.
3
What software versions are affected by CVE-2022-42232?
Simple Cold Storage Management System v1.0 is the affected software version.
4
What is the Common Weakness Enumeration (CWE) of CVE-2022-42232?
The CWE of CVE-2022-42232 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).
5
Is there a fix for CVE-2022-42232?
There is no specific fix mentioned, but it is recommended to update the Simple Cold Storage Management System software to the latest version to address this vulnerability.