Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-15820 | Rapid7 Nexpose versions 6.6.93 and earlier are susceptible to an SQL Injection vulnerability, whereby valid search operators are not defined. This lack of validation can allow a logged-in, authenticated attacker to manipulate the "ANY" and "OR" operators in the SearchCriteria and inject SQL code. This issue was fixed in Rapid7 Nexpose version 6.6.129. |
| Link | Providers |
|---|---|
| https://docs.rapid7.com/release-notes/nexpose/20220302/ |
|
No history.
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-09-16T17:48:14.153Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-0757
No data.
Status : Modified
Published: 2022-03-17T23:15:07.610
Modified: 2026-06-17T04:21:11.510
Link: CVE-2022-0757
No data.
OpenCVE Enrichment
No data.
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
EUVD