CVE-2022-21644
Dashboard / Vulnerabilities / CVE-2022-21644
Summary: SQL Injection via search in USOC
Details: USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch.php. In search terms provided by the user were not sanitized and were used directly to construct a sql statement. The only users permitted to search are site admins. Users are advised to upgrade as soon as possible. There are not workarounds for this issue.
References: https://github.com/Aaron-Junker/USOC/security/advisories/GHSA-89jg-6fr3-9q4h, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21644.json, https://nvd.nist.gov/vuln/detail/CVE-2022-21644, https://github.com/Aaron-Junker/USOC/commit/06217c66c8f9b114726b21633eabcd88ac9034aa
Affected packages
Package
Name:
Purl:
