VYPR
Medium severity5.9NVD Advisory· Published Jul 6, 2022· Updated Jun 17, 2026

CVE-2022-30619

CVE-2022-30619

Description

Editable SQL Queries behind Base64 encoding sending from the Client-Side to The Server-Side for a particular API used in legacy Work Center module. He attack is available for any authenticated user, in any kind of rule. under the function : /AgilePointServer/Extension/FetchUsingEncodedData in the parameter: EncodedData

Affected products

3
  • cpe:2.3:a:agilepoint:agilepoint_nx:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:agilepoint:agilepoint_nx:*:*:*:*:*:*:*:*range: <8.0
    • (no CPE)
  • Agile Point/Agile Point NXv5
    Range: 8.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.