CVE-2022-24121: SQL Injection
SQL Injection vulnerability discovered in Unified Office Total Connect Now that would allow an attacker to extract sensitive information through a cookie parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-24121.
What is the severity of the CVE-2022-24121 vulnerability?
The severity of CVE-2022-24121 vulnerability is high with a severity value of 7.5.
What is the affected software?
The affected software is Unified Office Total Connect Now.
How does the CVE-2022-24121 vulnerability work?
The CVE-2022-24121 vulnerability is a SQL Injection vulnerability that allows an attacker to extract sensitive information through a cookie parameter in Unified Office Total Connect Now.
Are there any references for CVE-2022-24121?
Yes, you can find references for CVE-2022-24121 at the following links: [Link 1](https://unifiedoffice.com/total-connect-now/) and [Link 2](https://www.coresecurity.com/core-labs/advisories/unified-office-total-connect-sql-injection).