CVE-2022-26959
Last modified
CVE-2022-26959 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ directory and the userID parameter of the login.jsp page in the /northstar/iphone/ directory. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ directory and the userID parameter of the login.jsp page in the /northstar/iphone/ directory. Exploitation of the SQL injection vulnerabilities allows full access to the database which contains critical data for organization’s that make full use of the software suite.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Globalnorthstar | Northstar Club Management | 6.3 |
References
- https://assura.atlassian.net/wiki/spaces/VULNS/pages/1842675717/CVE-2022-26959+Northstar+Club+Management+software+version+6.3+-+Full+Blind+Time-based+SQL+InjectionExploit, Issue Tracking, Third Party Advisory
- https://assura.atlassian.net/wiki/spaces/VULNS/pages/1842675717/CVE-2022-26959+Northstar+Club+Management+software+version+6.3+-+Full+Blind+Time-based+SQL+InjectionExploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-26959?
How severe is CVE-2022-26959?
How do I fix CVE-2022-26959?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-2695The Beaver Builder – WordPress Page Builder for WordPress is…5.4
- CVE-2022-26950Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open r…6.1
- CVE-2022-26951Archer 6.x through 6.10 (6.10.0.0) contains a reflected XSS …6.1
- CVE-2022-26952Digi Passport Firmware through 1.5.1,1 is affected by a buff…7.5
- CVE-2022-26953Digi Passport Firmware through 1.5.1,1 is affected by a buff…7.5
- CVE-2022-26954Multiple open redirect vulnerabilities in NopCommerce 4.10 t…6.1
- CVE-2022-2696The Restaurant Menu – Food Ordering System – Table Reservati…6.5
- CVE-2022-26960connector.minimal.php in std42 elFinder through 2.1.60 is af…9.1
- CVE-2022-26961Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS…5.4
- CVE-2022-26962Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under…5.4
- CVE-2022-26964Weak password derivation for export in Devolutions Remote De…7.5
- CVE-2022-26965In Pluck 4.7.16, an admin user can use the theme upload func…7.2
Are you affected by CVE-2022-26959?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
