VYPR
High severityNVD Advisory· Published Aug 24, 2022· Updated Aug 3, 2024

CVE-2022-37333

CVE-2022-37333

Description

SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows remote authenticated attackers to execute arbitrary SQL commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
exceedone/exmentPackagist
>= 5.0.0, < 5.0.35.0.3
exceedone/exmentPackagist
< 4.4.34.4.3
exceedone/laravel-adminPackagist
< 2.2.32.2.3
exceedone/laravel-adminPackagist
>= 3.0.0, < 3.0.13.0.1

Affected products

3
  • ghsa-coords2 versions
    >= 5.0.0, < 5.0.3+ 1 more
    • (no CPE)range: >= 5.0.0, < 5.0.3
    • (no CPE)range: < 2.2.3
  • Kajitori Co.,Ltd/Exmentv5
    Range: (PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.