CVE-2022-3792
Last modified
CVE-2022-3792 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye terminal operating system allows SQL Injection. This issue affects GullsEye terminal operating system: from unspecified before 5.0.13.. EPSS estimates a 14.19% chance of exploitation in the next 30 days.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye terminal operating system allows SQL Injection. This issue affects GullsEye terminal operating system: from unspecified before 5.0.13.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gullseye | Gullseye Terminal Operating System | < 5.0.13 |
References
- https://fordefence.com/cve-2022-3792-gullseye-terminal-operation-system/Exploit, Third Party Advisory
- https://omrylmz.com/cve-2022-3792-terminal-operation-system/Exploit, Third Party Advisory
- https://www.usom.gov.tr/bildirim/tr-22-0747-2Exploit, Third Party Advisory
- https://fordefence.com/cve-2022-3792-gullseye-terminal-operation-system/Exploit, Third Party Advisory
- https://omrylmz.com/cve-2022-3792-terminal-operation-system/Exploit, Third Party Advisory
- https://www.usom.gov.tr/bildirim/tr-22-0747-2Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3792?
How severe is CVE-2022-3792?
How do I fix CVE-2022-3792?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-37914Vulnerabilities in the web-based management interface of Aru…9.8
- CVE-2022-37915A vulnerability in the web-based management interface of Aru…9.8
- CVE-2022-37916Vulnerabilities in the AirWave Management Platform web-based…8.1
- CVE-2022-37917Vulnerabilities in the AirWave Management Platform web-based…8.1
- CVE-2022-37918Vulnerabilities in the AirWave Management Platform web-based…8.1
- CVE-2022-37919A vulnerability exists in the API of Aruba EdgeConnect Enter…7.5
- CVE-2022-37920Vulnerabilities in the Aruba EdgeConnect Enterprise command …7.2
- CVE-2022-37921Vulnerabilities in the Aruba EdgeConnect Enterprise command …7.2
- CVE-2022-37922Vulnerabilities in the Aruba EdgeConnect Enterprise command …7.2
- CVE-2022-37923Vulnerabilities in the Aruba EdgeConnect Enterprise command …7.2
- CVE-2022-37924Vulnerabilities in the Aruba EdgeConnect Enterprise command …7.2
- CVE-2022-37925A vulnerability within the web-based management interface of…6.1
Are you affected by CVE-2022-3792?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
