Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-38627: Security-Research/CVE-2022-38627.yaml at main · omarhashem123/Security-Research

Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.

CVE
#sql#vulnerability#git#php#auth

id: CVE-2022-38627

info:

name: Linear eMerge E3-Series - SQLite injection

author: omarhashem666

severity: critical

description: |

Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c,0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.

reference:

- https://github.com/omarhashem123/Security-Research/tree/main/CVE-2022-38627

- https://omar0x01.medium.com/15cebd072ed6

- https://nvd.nist.gov/vuln/detail/CVE-2022-38627

classification:

cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

cvss-score: 9.8

cve-id: CVE-2022-38627

tags: cve2022,emerge,nortek,linear,nice,sqli,github,cve

requests:

- method: GET

path:

- ‘{{BaseURL}}/badging/badge_template_print.php?tpl=aa.xml’

matchers:

- type: word

part: body

words:

- ‘Exception : SQLSTATE[HY000]: General error: 1’

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda