CVE-2022-23168 is a critical SQL injection vulnerability (CWE-89) affecting amodat mobile_application_gateway, allowing an unauthenticated attacker to gain full database access via the username parameter in the login panel. With a CVSS score of 9.8 (CRITICAL), it presents a low-complexity attack vector with high impact on confidentiality, integrity, and availability. While not listed in CISA KEV and lacking public Metasploit, Nuclei, or ExploitDB modules, the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.12.00.09CPE matchmatch criteria | cpe:2.3:a:amodat:mobile_application_gateway:*:*:*:*:*:*:*:* | ||
>= 7.12.00.08, <= 7.12.00.09CPE match | cpe:2.3:a:amodat:amodat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.