CVE-2022-27434
CRITICALUNIT4 TETA Mobile Edition < 29.5 - SQL Injection via ProfileName Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-27434. PoCs published by LongWayHomie.
AI-analyzed exploit summary This repository documents a SQL injection vulnerability (CVE-2022-27434) in UNIT4 TETA Mobile Edition 29HF13 via the ProfileName parameter in the errorReporting page. It includes screenshots of the request and response demonstrating the vulnerability but lacks exploit code.
Description
UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page.
Exploits (1)
This repository documents a SQL injection vulnerability (CVE-2022-27434) in UNIT4 TETA Mobile Edition 29HF13 via the ProfileName parameter in the errorReporting page. It includes screenshots of the request and response demonstrating the vulnerability but lacks exploit code.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H