Vulnerability Description
UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unit4 | Teta | <= 29.5 |
Related Weaknesses (CWE)
References
- https://github.com/LongWayHomie/CVE-2022-27434ExploitThird Party Advisory
- https://teta.unit4.com/plProductVendor Advisory
- https://github.com/LongWayHomie/CVE-2022-27434ExploitThird Party Advisory
- https://teta.unit4.com/plProductVendor Advisory
FAQ
What is CVE-2022-27434?
CVE-2022-27434 is a vulnerability with a CVSS score of 9.8 (CRITICAL). UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page.
How severe is CVE-2022-27434?
CVE-2022-27434 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-27434?
Check the references section above for vendor advisories and patch information. Affected products include: Unit4 Teta.