Record summary

CVE-2022-1883 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

SQL Injection in GitHub repository camptocamp/terraboard prior to 2.2.0.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 15, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListBefore 2.2.0affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHTerraboard <2.2.0 - SQL InjectionCVSS 8.8

Terraboard prior to 2.2.0 contains a SQL injection vulnerability. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.

Remediation

Upgrade Terraboard to version 2.2.0 or later to mitigate the SQL Injection vulnerability.

WeaknessesCWE-89
Authorsedoardottt
Template tagstime-based-sqlicvecve2022terraboardsqlihuntrcamptocampvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:camptocamp:terraboard:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2