CVE-2022-24121

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
03/02/2022
Last modified:
08/02/2022

Description

SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information through a cookie parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:unifiedoffice:total_connect_now:-:*:*:*:*:*:*:*
cpe:2.3:o:centos:centos:6.0:*:*:*:*:*:*:*