CVE-2022-1731
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
16/05/2022
Last modified:
25/05/2022
Description
Metasonic Doc WebClient 7.0.14.0 / 7.0.12.0 / 7.0.3.0 is vulnerable to a SQL injection attack in the username field. SSO or System authentication are required to be enabled for vulnerable conditions to exist.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:allgeier:metasonic_doc_webclient:7.0.3.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:allgeier:metasonic_doc_webclient:7.0.12.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:allgeier:metasonic_doc_webclient:7.0.14.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



