CVE-2022-3792
critical · 9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye terminal operating system allows SQL Injection. This issue affects GullsEye terminal operating system: from unspecified before 5.0.13.
9.8
CVSS
14.2%
EPSS (exploit prob.)
96th
EPSS percentile
2023-01-10
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| gullseye | gullseye_terminal_operating_system | < 5.0.13 |
Check a specific version with /api/v1/cve/match.
References
- https://fordefence.com/cve-2022-3792-gullseye-terminal-operation-system/
- https://omrylmz.com/cve-2022-3792-terminal-operation-system/
- https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-22-0747-2
- https://www.usom.gov.tr/bildirim/tr-22-0747-2
- https://fordefence.com/cve-2022-3792-gullseye-terminal-operation-system/
- https://omrylmz.com/cve-2022-3792-terminal-operation-system/
- https://www.usom.gov.tr/bildirim/tr-22-0747-2
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-3792