Security Advisory
CVE-2022-44015
9.8
CRITICAL
Vulnerability Description
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary commands on the MSSQL server via the xp_cmdshell extended procedure.
Published Date
December 25, 2022
Official Source
NIST NVD Advisory