CVE-2022-46442: SQL Injection
Published Dec 27, 2022
·Updated
dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys sql n query.php there are no restrictions on the sql query.
Affected Software
1 affected component
DedeCMS Dedecms<=5.7.102
Event History
Dec 27, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-46442?
CVE-2022-46442 is a vulnerability in dedecms version <=V5.7.102 that allows for SQL Injection.
2
How severe is CVE-2022-46442?
CVE-2022-46442 has a severity rating of 9.8, which is considered critical.
3
What is the affected software in CVE-2022-46442?
The affected software in CVE-2022-46442 is dedecms version <=V5.7.102.
4
What is the CWE of CVE-2022-46442?
The CWE of CVE-2022-46442 is CWE-89, which is for SQL Injection vulnerabilities.
5
How can I fix CVE-2022-46442?
To fix CVE-2022-46442, you should update dedecms to a version higher than V5.7.102 that includes the necessary restrictions on SQL queries.