9.8
CVE-2022-50694
- EPSS 0.85%
- Veröffentlicht 30.12.2025 22:41:34
- Zuletzt bearbeitet 16.01.2026 19:16:10
- Erkennungen
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x SQL Injection via Username Parameter
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through the username parameter to bypass authentication and potentially access unauthorized database information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sound4 ≫ Impact Firmware Version 2.15
Sound4 ≫ Impact Firmware Version 1.69
Sound4 ≫ Pulse Firmware Version 2.15
Sound4 ≫ Pulse Firmware Version 1.69
Sound4 ≫ First Firmware Version 2.15
Sound4 ≫ First Firmware Version 1.69
Sound4 ≫ Impact Eco Firmware Version 1.16
Sound4 ≫ Pulse Eco Firmware Version 1.16
Sound4 ≫ Big Voice4 Firmware Version 1.2
Sound4 ≫ Big Voice2 Firmware Version 1.30
Sound4 ≫ Wm2 Firmware Version 1.11
Sound4 ≫ Stream Extension Version 2.4.29
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.85% | 0.551 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| disclosure@vulncheck.com | 8.8 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
https://www.sound4.com/
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5727.php
https://packetstormsecurity.com/files/170254/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-username-SQL-Injection.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/247947
https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-sql-injection-via-username-parameter