« Volver al listado

CVE-2022-38118

Estado: ModificadaAlta (8.8)—

OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-injection to access, modify, delete database, perform system operations and disrupt service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-38118",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "twcert@cert.org.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "twcert@cert.org.tw",
      "affectedData": [
        {
          "vendor": "HGiga",
          "product": "OAKlouds",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "OAKlouds-mol_metting-2.0-163"
            }
          ],
          "platforms": [
            "OAKlouds-mol_metting-2.0"
          ]
        },
        {
          "vendor": "HGiga",
          "product": "OAKlouds",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "versionType": "custom",
              "lessThanOrEqual": "OAKlouds-mol_metting-3.0-163"
            }
          ],
          "platforms": [
            "OAKlouds-mol_metting-3.0"
          ]
        }
      ]
    }
  ],
  "published": "2022-08-30T05:15:08.047",
  "references": [
    {
      "url": "https://www.chtsecurity.com/news/0a893178-5c64-4f1c-87f1-95cbf1e17c87",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-6461-25c4b-1.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.chtsecurity.com/news/0a893178-5c64-4f1c-87f1-95cbf1e17c87",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-6461-25c4b-1.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "twcert@cert.org.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-injection to access, modify, delete database, perform system operations and disrupt service."
    },
    {
      "lang": "es",
      "value": "La Sala de Reuniones del Portal OAKlouds presenta una comprobación insuficiente para la entrada de usuarios. Un atacante remoto con privilegio de usuario general puede llevar a cabo una inyección SQL para acceder, modificar, eliminar la base de datos, llevar a cabo operaciones del sistema e interrumpir el servicio"
    }
  ],
  "lastModified": "2026-06-17T04:56:08.403",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hgiga:oaklouds_portal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "286C164A-D522-471F-903B-1EB82E7F9BBD",
              "versionEndIncluding": "2.0-163",
              "versionStartIncluding": "2.0"
            },
            {
              "criteria": "cpe:2.3:a:hgiga:oaklouds_portal:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1368AA8-FB06-4A14-8A2C-335E51A79376",
              "versionEndIncluding": "3.0-163",
              "versionStartIncluding": "3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "twcert@cert.org.tw"
}