CVE Published: 09/02/2023 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: TR-CERT |
Vendor: Group Arge Energy and Control Systems |
Product: Smartpower Web Status : PUBLISHED
CVE-2022-4557 Description
Improper Neutralization of Special Elements used in an SQL Command (\'SQL Injection\') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection.This issue affects Smartpower Web: before 23.01.01.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* HIGH
Weakness Enumeration (CWE)
CWE-ID: CWE-89 CWE Name: CWE-89 Improper Neutralization of Special Elements used in an SQL Command (
SQL Injection
) Source: Group Arge Energy and Control Systems
Common Attack Pattern Enumeration and Classification (CAPEC)