NVD disclosure day

Published threat advisories for December 2, 2022

CVE advisoryCRITICAL

CVE-2022-44945

Rukovoditel SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in Rukovoditel software, allowing unauthenticated attackers to manipulate database queries via the network. This could lead to unauthorized access, modification, or deletion of sensitive data, posing a critical risk if the software is in use.

CVE advisoryCRITICAL

CVE-2022-44291

webTareas SQL Injection Vulnerability in phasesets.php

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in webTareas's phasesets.php allows unauthenticated attackers to manipulate the database via network requests, potentially leading to unauthorized access or modification of sensitive data. Readers should care because this critical flaw could impact data integrity and access.

CVE advisoryCRITICAL

CVE-2022-44290

webTareas SQL Injection Vulnerability in deleteapprovalstages.php

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the webTareas application's `deleteapprovalstages.php` script, allowing unauthenticated attackers to manipulate the database via the `id` parameter. This could lead to unauthorized data access, modification, or deletion if the application is reachable.