Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-09-02T00:00:00
Updated: 2024-08-04T14:51:10.946Z
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-22669
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-09-02T18:15:11.607
Modified: 2024-11-21T05:13:21.890
Link: CVE-2020-22669
Redhat
No data.