Loading
Generated remediation guidance and an executive summary. No account required.
A SQL injection vulnerability exists in the “reporting job editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.
Use CWE-78, Sciencelogic vendor hub and Sl1 product page to widen CVE-2022-48589 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-9537, CVE-2022-48604 and CVE-2022-48603 for nearby disclosures in the same product family.