HIGH
IBAX go-ibax rowsInfo sql injection
Published Nov 1, 2022
8.8
HIGHCVSS 3.1
EPSS 30.08%
Description
A vulnerability, which was classified as critical, was found in IBAX go-ibax. This affects an unknown part of the file /api/v2/open/rowsInfo. The manipulation of the argument order leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-212637 was assigned to this vulnerability.
Affected products
No data.
No Red Hat product state for this CVE.
github.com/IBAX-io/go-ibax
Go
Introduced 0 Fixed 1.4.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/IBAX-io/go-ibax | 0 | 1.4.2 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7381 Advisory
- https://github.com/IBAX-io/go-ibax/commit/b0183d8e550836dc50282ee74ff421ee41b25a37
- https://github.com/IBAX-io/go-ibax/issues/2062 Issue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-m738-584h-26p6 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3801
- https://vuldb.com/?id.212637 Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7381 | Advisory | |
| https://github.com/IBAX-io/go-ibax/commit/b0183d8e550836dc50282ee74ff421ee41b25a37 | ||
| https://github.com/IBAX-io/go-ibax/issues/2062 | Issue TrackingThird Party Advisory | |
| https://github.com/advisories/GHSA-m738-584h-26p6 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3801 | ||
| https://vuldb.com/?id.212637 | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Nov 1, 2022
Updated Aug 3, 2024
Reserved Nov 1, 2022
Link CVE-2022-3801
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-7381 GHSA-M738-584H-26P6 Assigner VulDB
Published Nov 1, 2022
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2022-7381