CVE-2022-25225

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
10/03/2022
Last modified:
16/03/2022

Description

Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default installation (PostgreSQL) by exploiting this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:softinventive:network_olympus:1.8.0:*:*:*:*:*:*:*