Vulnerability Description
The Le-yan dental management system contains an SQL-injection vulnerability. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to acquire administrator’s privilege and perform arbitrary operations on the system or disrupt service.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Le-Yan Dental Management System Project | Le-Yan Dental Management System | 2.8.5 |
Related Weaknesses (CWE)
References
- https://www.twcert.org.tw/tw/cp-132-5509-80f05-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-5509-80f05-1.htmlThird Party Advisory
FAQ
What is CVE-2022-22055?
CVE-2022-22055 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Le-yan dental management system contains an SQL-injection vulnerability. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to acquire administrator’...
How severe is CVE-2022-22055?
CVE-2022-22055 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-22055?
Check the references section above for vendor advisories and patch information. Affected products include: Le-Yan Dental Management System Project Le-Yan Dental Management System.