VYPR
Unrated severityNVD Advisory· Published Aug 9, 2023· Updated Oct 10, 2024

CVE-2022-48603

CVE-2022-48603

Description

A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated SQL injection in ScienceLogic SL1's message viewer iframe allows arbitrary query execution against the backend database.

Vulnerability

A SQL injection vulnerability exists in the "message viewer iframe" feature of ScienceLogic SL1 versions up to and including 11.1.2 [1]. The feature takes user-controlled input without sanitization and passes it directly into a SQL query, enabling arbitrary SQL injection before execution against the database [1].

Exploitation

An attacker can access the vulnerable iframe endpoint without authentication. By crafting a malicious SQL payload within the input parameter, the attacker can inject arbitrary SQL commands, which are then executed by the database backend [1]. No special privileges or network position beyond network access to the SL1 instance is required.

Impact

Successful exploitation allows an attacker to execute arbitrary SQL queries against the ScienceLogic SL1 database. This can lead to unauthorized reading, modification, or deletion of sensitive data, including credentials, configuration, and monitoring information. The attacker gains full database-level access based on the permissions of the database user [1].

Mitigation

ScienceLogic has addressed this vulnerability in a newer release. Users must update to the latest version of ScienceLogic SL1 [1]. No workarounds are available in the referenced advisory. If an upgrade is not immediately possible, restrict network access to the SL1 interface as a compensating control.

References
  1. CVE-2022-48603

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.