CVE-2022-44015
Summary
| CVE | CVE-2022-44015 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-25 05:15:00 UTC |
| Updated | 2023-01-05 04:49:00 UTC |
| Description | An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary commands on the MSSQL server via the xp_cmdshell extended procedure. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Simmeth | Lieferantenmanager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Critical Vulnerabilities in Simmeth System GmbH Supplier Manager (Lieferantenmanager) | MISC | sec-consult.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.