VYPR
Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Oct 10, 2024

CVE-2022-48588

CVE-2022-48588

Description

A SQL injection vulnerability exists in the “schedule editor decoupled” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SQL injection in ScienceLogic SL1's schedule editor decoupled feature allows unauthenticated attackers to execute arbitrary queries.

Vulnerability

A SQL injection vulnerability exists in the “schedule editor decoupled” feature of ScienceLogic SL1 versions 11.1.2 and earlier. The feature takes unsanitized user-controlled input and passes it directly to a SQL query, allowing the injection of arbitrary SQL statements before execution against the database [1].

Exploitation

An attacker can exploit this vulnerability by sending crafted input to the “schedule editor decoupled” feature. No authentication or special network position is required; the feature is accessible over the network. The attacker simply supplies malicious SQL payloads in the unsanitized parameter, which are then executed by the database [1].

Impact

Successful exploitation allows an attacker to execute arbitrary SQL commands against the ScienceLogic SL1 database. This can lead to information disclosure, data modification, or complete compromise of the database [1]. The attacker may be able to read sensitive information, modify or delete records, or potentially gain further access to the underlying system.

Mitigation

ScienceLogic recommends updating to the latest version of SL1. There is no fixed version number explicitly provided in the references, but the vendor has been notified and disclosure occurred on August 9, 2023 [1]. If upgrading is not immediately possible, ensure the “schedule editor decoupled” feature is not exposed to untrusted users or networks.

References
  1. CVE-2022-48588

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.