CVE-2022-45135SQL Injection in Software Foundation Apache Cocoon

CWE-89SQL Injection4 documents4 sources
Severity
9.8CRITICALNVD
EPSS
1.5%
top 18.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDapache/cocoon2.2.02.3.0
CVEListV5apache_software_foundation/apache_cocoon2.2.02.3.0

🔴Vulnerability Details

3
GHSA
Apache Cocoon SQL Injection vulnerability2023-11-30
CVEList
Apache Cocoon: SQL injection in DatabaseCookieAuthenticatorAction2023-11-30
OSV
Apache Cocoon SQL Injection vulnerability2023-11-30
CVE-2022-45135 — SQL Injection | cvebase