CVE-2022-41223

The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection...

Basic Information

CVE State
PUBLISHED
Reserved Date
September 21, 2022
Published Date
November 22, 2022
Last Updated
January 28, 2025
Vendor
n/a
Product
n/a
Description
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.

CVSS Scores

CVSS v3.1

6.8 - MEDIUM

Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2023-02-21 00:00:00 UTC) Source
Used in Malware
Yes (added 2023-02-21 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2023-02-21 00:00:00 UTC