PT-2022-24448 · Archery · Archery

·

CVE-2022-38542

·

Published

2022-09-13

·

Updated

2022-10-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Archery versions 1.4.0 through 1.8.5
Description The issue is related to a SQL injection vulnerability. It occurs via the ThreadIDs parameter in the "kill session" interface.
Recommendations For versions 1.4.0 through 1.8.5, upgrade to version 1.9.0 or above to resolve the issue. As a temporary workaround, consider restricting access to the kill session interface until the update is applied. Avoid using the ThreadIDs parameter in the affected interface until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-38542

Affected Products

Archery