CVE-2022-48684

HIGH

Logpoint SIEM < 7.1.1 - Authenticated Remote Code Execution via Search Template Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search template. The search template uses jinja templating for generating dynamic data. This could be abused to achieve code execution. Any user with access to create a search template can leverage this to execute code as the loginspect user.

Scores

CVSS v3 8.4
EPSS 0.0064
EPSS Percentile 46.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
logpoint/siem < 7.1.1
Published Apr 27, 2024
Tracked Since Feb 18, 2026