CVE-2022-34652
Last modified
CVE-2022-34652 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. EPSS estimates a 0.91% chance of exploitation in the next 30 days.
Description
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to inject SQL by manipulating the description parameter.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wwbn | Avideo | 11.6 |
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1551Technical Description, Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1551Technical Description, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-34652?
How severe is CVE-2022-34652?
How do I fix CVE-2022-34652?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-34643RISCV ISA Sim commit ac466a21df442c59962589ba296c702631e041b…5.5
- CVE-2022-34648Authenticated (author+) Stored Cross-Site Scripting (XSS) vu…5.4
- CVE-2022-34649Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2022-3465A vulnerability classified as critical was found in Mediabri…9.8
- CVE-2022-34650Multiple Authenticated (contributor or higher user role) Sto…5.4
- CVE-2022-34651In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before …7.5
- CVE-2022-34653Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2022-34654Cross-Site Request Forgery (CSRF) in Virgial Berveling's Man…8.8
- CVE-2022-34655In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.…7.5
- CVE-2022-34656Authenticated (admin+) Cross-Site Scripting (XSS) vulnerabil…4.8
- CVE-2022-34657Improper input validation in firmware for some Intel(R) PCSD…4.4
- CVE-2022-34658Multiple Authenticated (contributor+) Persistent Cross-Site …5.4
Are you affected by CVE-2022-34652?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
