VYPR
Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Oct 10, 2024

CVE-2022-48584

CVE-2022-48584

Description

A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A command injection in ScienceLogic SL1's download and convert report feature allows unauthenticated remote code execution as the web server user.

Vulnerability

A command injection vulnerability exists in the download and convert report feature of ScienceLogic SL1 [1]. The application takes unsanitized user-controlled input and passes it directly to a shell command [1]. This allows for the injection of arbitrary commands to the underlying operating system [1]. Affected versions are ScienceLogic SL1 11.1.2 and earlier [1].

Exploitation

An attacker can exploit this vulnerability by sending specially crafted requests to the download and convert report endpoint [1]. No authentication is required to reach the vulnerable feature [1]. The attacker simply needs network access to the SL1 appliance [1].

Impact

Successful exploitation allows an attacker to execute arbitrary operating system commands with the privileges of the web server user [1]. This can lead to full compromise of the SL1 appliance [1], including data exfiltration, installation of backdoors, or further lateral movement within the network.

Mitigation

ScienceLogic released a fix in version 11.1.3 and later [1]. Users should update to the latest version of ScienceLogic SL1 [1]. No workarounds have been publicly disclosed [1].

References
  1. CVE-2022-48584

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.