Vulnerability Description
SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information through a cookie parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unifiedoffice | Total Connect Now | - |
| Centos | Centos | 6.0 |
Related Weaknesses (CWE)
References
- https://unifiedoffice.com/total-connect-now/ProductVendor Advisory
- https://www.coresecurity.com/core-labs/advisories/unified-office-total-connect-sExploitThird Party Advisory
- https://unifiedoffice.com/total-connect-now/ProductVendor Advisory
- https://www.coresecurity.com/core-labs/advisories/unified-office-total-connect-sExploitThird Party Advisory
FAQ
What is CVE-2022-24121?
CVE-2022-24121 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information through a cookie parameter.
How severe is CVE-2022-24121?
CVE-2022-24121 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24121?
Check the references section above for vendor advisories and patch information. Affected products include: Unifiedoffice Total Connect Now, Centos Centos.