CVE-2022-24691

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
18/07/2022
Last modified:
27/07/2022

Description

An issue was discovered in DSK DSKNet 2.16.136.0 and 2.17.136.5. A SQL Injection vulnerability allows authenticated users to taint database data and extract sensitive information via crafted HTTP requests. The type of SQL Injection is blind boolean based.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dsk:dsknet:2.16.136.0:*:*:*:*:*:*:*
cpe:2.3:a:dsk:dsknet:2.17.136.5:*:*:*:*:*:*:*