SQL Injection Flaw in ScienceLogic SL1 Reporting Feature
CVE-2022-48598
8.8HIGH
What is CVE-2022-48598?
A SQL injection vulnerability exists in the 'reporter events type date' feature of ScienceLogic SL1, allowing attackers to manipulate SQL queries. By providing unsanitized user input directly to the database, unauthorized parties can execute arbitrary SQL commands, posing significant risks to data integrity and confidentiality.
Affected Version(s)
SL 1 11.1.2