CVE-2025-58780
- EPSS 0.06%
- Veröffentlicht 05.09.2025 00:00:00
- Zuletzt bearbeitet 08.09.2025 21:15:34
index.em7 in ScienceLogic SL1 before 12.1.1 allows SQL Injection via a parameter in a request. NOTE: this is disputed by the Supplier because it "inaccurately describes the vulnerability."
CVE-2024-9537
- EPSS 63.91%
- Veröffentlicht 18.10.2024 15:15:04
- Zuletzt bearbeitet 03.11.2025 18:55:13
ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made ava...
CVE-2022-48604
- EPSS 0.07%
- Veröffentlicht 09.08.2023 19:15:14
- Zuletzt bearbeitet 21.11.2024 07:33:35
A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed agai...
CVE-2022-48603
- EPSS 0.07%
- Veröffentlicht 09.08.2023 19:15:14
- Zuletzt bearbeitet 21.11.2024 07:33:35
A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being execut...
CVE-2022-48602
- EPSS 0.07%
- Veröffentlicht 09.08.2023 19:15:14
- Zuletzt bearbeitet 21.11.2024 07:33:35
A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being execute...
CVE-2022-48601
- EPSS 0.07%
- Veröffentlicht 09.08.2023 19:15:14
- Zuletzt bearbeitet 21.11.2024 07:33:35
A SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being execute...
CVE-2022-48593
- EPSS 0.07%
- Veröffentlicht 09.08.2023 19:15:13
- Zuletzt bearbeitet 21.11.2024 07:33:33
A SQL injection vulnerability exists in the “topology data service” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being execut...
CVE-2022-48600
- EPSS 0.07%
- Veröffentlicht 09.08.2023 19:15:13
- Zuletzt bearbeitet 21.11.2024 07:33:34
A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against ...
CVE-2022-48599
- EPSS 0.07%
- Veröffentlicht 09.08.2023 19:15:13
- Zuletzt bearbeitet 21.11.2024 07:33:34
A SQL injection vulnerability exists in the “reporter events type” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being execute...
CVE-2022-48598
- EPSS 0.07%
- Veröffentlicht 09.08.2023 19:15:13
- Zuletzt bearbeitet 21.11.2024 07:33:34
A SQL injection vulnerability exists in the “reporter events type date” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being ex...