Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 09 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GestSup versions up to and including 3.2.56 contain multiple SQL injection vulnerabilities in the asset list functionality. Multiple request parameters used to filter, search, or sort assets are incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Successful exploitation can result in unauthorized access to or modification of database contents depending on database privileges. | |
| Title | GestSup <= 3.2.56 Multiple SQL Injections in Asset List | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-09T18:37:26.775Z
Reserved: 2026-01-06T16:47:17.184Z
Link: CVE-2026-22197
Updated: 2026-01-09T17:48:02.889Z
Status : Received
Published: 2026-01-09T17:15:55.170
Modified: 2026-01-09T17:15:55.170
Link: CVE-2026-22197
No data.
OpenCVE Enrichment
No data.