CVE-2022-38488
critical · 9.8logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.
9.8
CVSS
14.2%
EPSS (exploit prob.)
96th
EPSS percentile
2022-12-14
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| logrocket-oauth2-example_project | logrocket-oauth2-example | <= 2020-05-27 |
Check a specific version with /api/v1/cve/match.
References
- https://archive.ph/PecmD
- https://archive.ph/VlGDa
- https://blog.logrocket.com/implement-oauth-2-0-node-js/
- https://github.com/diogosouza/logrocket-oauth2-example
- https://github.com/secoats/cve/tree/master/CVE-2022-38488_sqli_logrocket-oauth2-example
- https://archive.ph/PecmD
- https://archive.ph/VlGDa
- https://blog.logrocket.com/implement-oauth-2-0-node-js/
- https://github.com/diogosouza/logrocket-oauth2-example
- https://github.com/secoats/cve/tree/master/CVE-2022-38488_sqli_logrocket-oauth2-example
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-38488