Back

HIGH

Authenticated SQL Injection on Alerts in Guardian/CMC before 22.5.2

Published May 4, 2023

Description

Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.

Affected products

Remediation

Vendor solution

Upgrade to version >= 22.5.2

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Nozomi
Published May 4, 2023
Updated Aug 3, 2024
Reserved Dec 1, 2022
CISA Vulnrichment
Updated Jul 16, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a