VYPR
Unrated severityNVD Advisory· Published Mar 2, 2023· Updated Mar 7, 2025

CVE-2022-46501

CVE-2022-46501

Description

Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A SQL injection vulnerability exists in Accruent Maintenance Connection 2021 and 2022.2 via the E-Mail to Work Order function, allowing potential unauthorized data access.

Vulnerability

Accruent LLC Maintenance Connection versions 2021 (all) and 2022.2 contain a SQL injection vulnerability in the E-Mail to Work Order function [1]. The vulnerable code path is reachable when an email is processed to create or update work orders, and the input is not properly sanitized. All deployments of these versions are affected unless patched.

Exploitation

An attacker can exploit this vulnerability by sending a crafted email that is processed by the vulnerable E-Mail to Work Order function. The attacker needs only the ability to send an email to the system's configured email-to-work-order address; no authentication is required for the email itself, but the system must be configured to process such emails. The injection occurs during email parsing before database query execution. No user interaction is needed beyond the email being received and processed by the system.

Impact

Successful exploitation allows an attacker to execute arbitrary SQL queries against the back-end database. This can lead to unauthorized reading or modification of sensitive data, including work orders, user credentials, and other operational information. The attacker can potentially escalate privileges or gain persistent access to the system, resulting in a compromise of confidentiality, integrity, and availability [2].

Mitigation

Accruent has provided a fix for all remaining systems and advises installing the 2023 upgrade that was made available in March 2024 [2]. Users of Maintenance Connection 2021 or 2022.2 should upgrade to the 2023 release or later to remediate this vulnerability. No workarounds have been publicly documented; the only recommended action is to apply the vendor-supplied patch.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.