VYPR
Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Oct 10, 2024

CVE-2022-48586

CVE-2022-48586

Description

A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A SQL injection vulnerability in ScienceLogic SL1's json walker feature allows attackers to execute arbitrary SQL queries, leading to database compromise.

Vulnerability

A SQL injection vulnerability exists in the json walker feature (also referred to as the admin brand portal feature) of ScienceLogic SL1. The application takes unsanitized user-controlled input and passes it directly to a SQL query, allowing for the injection of arbitrary SQL. Affected versions include ScienceLogic SL1 up to and including version 11.1.2 [1].

Exploitation

An attacker with network access to the ScienceLogic SL1 instance can send crafted input to the vulnerable endpoint. No authentication is explicitly required, though the feature may be part of the administrative interface. The attacker can inject SQL commands that are executed against the database.

Impact

Successful exploitation allows the attacker to execute arbitrary SQL statements. This can lead to unauthorized disclosure of sensitive data, modification or deletion of database records, and potential escalation to full database compromise.

Mitigation

ScienceLogic recommends updating to the latest version of SL1. The advisory does not specify a patched version number; users should contact ScienceLogic support for the appropriate update [1]. No workarounds are provided.

References
  1. CVE-2022-48586

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.