High severity7.2NVD Advisory· Published Mar 10, 2022· Updated Jun 17, 2026
CVE-2022-25225
CVE-2022-25225
Description
Network Olympus version 1.8.0 allows an authenticated admin user to inject SQL queries in '/api/eventinstance' via the 'sqlparameter' JSON parameter. It is also possible to achieve remote code execution in the default installation (PostgreSQL) by exploiting this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:softinventive:network_olympus:1.8.0:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: =1.8.0
Patches
Vulnerability mechanics
References
2- fluidattacks.com/advisories/spinetta/nvdExploitThird Party Advisory
- www.network-olympus.com/monitoring/nvdProductVendor Advisory
News mentions
0No linked articles in our index yet.