Amodat is a provider of mobile application gateway solutions, with disclosed vulnerabilities centered on SQL injection flaws affecting its core gateway product. The observed weakness class reflects input-handling gaps common to web-tier and API-gateway components; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Amodat over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23168CRITICAL The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: username: admin'-- | Jun 13, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-23167CRITICAL Attacker crafts a GET request to: /mobile/downloadfile.aspx? Filename =../.. /windows/boot.ini the LFI is UNAUTHENTICATED. | Jun 13, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-23169HIGH attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel. | Jun 13, 2022 | 7.2 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Amodat.
Media articles that mention a CVE ID that affects a product developed by Amodat — matched by CVE ID, not by vendor name.