VYPR
Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Oct 10, 2024

CVE-2022-48590

CVE-2022-48590

Description

A SQL injection vulnerability exists in the “admin dynamic app mib errors” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A SQL injection vulnerability in ScienceLogic SL1's admin dynamic app mib errors feature allows authenticated attackers to execute arbitrary SQL queries, potentially compromising the database.

Vulnerability

The admin dynamic app mib errors feature in ScienceLogic SL1 versions up to and including 11.1.2 contains a SQL injection vulnerability. User-controlled input is not sanitized before being passed directly to a SQL query, allowing an attacker to inject arbitrary SQL statements [1].

Exploitation

An attacker must have network access to the ScienceLogic SL1 administrative interface and valid credentials to access the vulnerable feature. By crafting malicious input in the affected parameter, the attacker can inject SQL commands that are executed against the database [1].

Impact

Successful exploitation allows the attacker to execute arbitrary SQL queries, leading to potential data exfiltration, modification, or deletion. The attacker may gain unauthorized access to sensitive information stored in the database [1].

Mitigation

ScienceLogic recommends updating to the latest version of SL1. No specific patched version is mentioned in the advisory, but users should apply the most recent update available. The vendor was notified in September 2022 and the vulnerability was publicly disclosed in August 2023 [1].

References
  1. CVE-2022-48590

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.