01642 06 11 11 Arrange Call

SQL Injection Vulnerability in On-Premise Allows Data Exfiltration

CVE-2022-1358 · MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N

CVE-2022-1358

The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate and dump all data held in the cnMaestro database.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.