CVE-2022-28132
Last modified
CVE-2022-28132 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. By exploiting this flaw, attackers can bypass authentication mechanisms, view sensitive information stored in the database, and potentially exfiltrate data.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2022-28132?
How severe is CVE-2022-28132?
How do I fix CVE-2022-28132?
Are you affected by CVE-2022-28132?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
