CVE-2022-27434

CRITICAL

UNIT4 TETA Mobile Edition < 29.5 - SQL Injection via ProfileName Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-27434. PoCs published by LongWayHomie.

AI-analyzed exploit summary This repository documents a SQL injection vulnerability (CVE-2022-27434) in UNIT4 TETA Mobile Edition 29HF13 via the ProfileName parameter in the errorReporting page. It includes screenshots of the request and response demonstrating the vulnerability but lacks exploit code.

Description

UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page.

Exploits (1)

nomisec WRITEUP 1 stars
by LongWayHomie · poc
https://github.com/LongWayHomie/CVE-2022-27434

This repository documents a SQL injection vulnerability (CVE-2022-27434) in UNIT4 TETA Mobile Edition 29HF13 via the ProfileName parameter in the errorReporting page. It includes screenshots of the request and response demonstrating the vulnerability but lacks exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: UNIT4 TETA Mobile Edition 29HF13
Auth required
Prerequisites: Access to the errorReporting page · Valid session or authentication
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Product, Vendor Advisory x_refsource_misc
https://teta.unit4.com/pl
Exploit, Third Party Advisory x_refsource_misc
https://github.com/LongWayHomie/CVE-2022-27434

Scores

CVSS v3 9.8
EPSS 0.0108
EPSS Percentile 60.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
unit4/teta < 29.5
Published Jul 18, 2022
Tracked Since Feb 18, 2026