CVE-2022-37333

HIGH
Published Aug 24, 20223y ago · Modified Jun 17, 20262w ago
8.8 CVSS 3.1
High
Find Similar
Published Aug 24, 2022 3y ago
Last Modified Jun 17, 2026 2w ago

Description

SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0 and earlier, (PHP7) exceedone/exment v4.4.2 and earlier and exceedone/laravel-admin v2.2.2 and earlier) allows remote authenticated attackers to execute arbitrary SQL commands.

CVSS Details

Base Score
8.8
Exploitability
2.8
Impact
5.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

No active exploitation signals — not in CISA KEV and no EPSS score yet.

Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-89 SQL Injection Injection

Affected Products 2

VendorProductVersionRange
exceedoneexment* ≤5.0.2
exceedonelaravel-admin* ≤3.0.0

References 3

  • exment.net https://exment.net/docs/#/release_note?id=v503-20220817
    PatchRelease NotesVendor Advisory
  • exment.net https://exment.net/docs/#/weakness/20220817
    MitigationPatchVendor Advisory
  • jvn.jp https://jvn.jp/en/jp/JVN46239102/index.html
    Third Party Advisory

Remediation

  • exment.net https://exment.net/docs/#/release_note?id=v503-20220817
    PatchRelease NotesVendor Advisory
  • exment.net https://exment.net/docs/#/weakness/20220817
    MitigationPatchVendor Advisory