peter bassill · operator
$ cve CVE-2022-47870 JSON

CVE-2022-47870 EXPLOIT

6.1
MEDIUM · CVSS 3.1 · EPSS 2.2% (pctl 82)

Patch early

A public exploit exists.

Description

A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to inject arbitrary web Script or HTML via the returnUrl parameter.

Scoring

CVSS6.1 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS2.23% — more likely to be exploited than 82% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2023-04-04
Last modified2026-06-17

Affected (1)

VendorProduct
red-gatesql monitor

Public exploits

SourceTitleDate
exploit-dbSQL Monitor 12.1.31.893 - Cross-Site Scripting (XSS)2023-04-03

References

→ the Explorer  ·  watch your stack  ·  NVD