ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific API parameters to acquire database schema or access data.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-31219 | ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific API parameters to acquire database schema or access data. |
Fixes
Solution
Update version to 1.4.3.2
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-6056-b0d90-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T02:42:16.801Z
Reserved: 2022-03-08T00:00:00
Link: CVE-2022-26669
No data.
Status : Modified
Published: 2022-06-20T06:15:08.903
Modified: 2024-11-21T06:54:17.800
Link: CVE-2022-26669
No data.
OpenCVE Enrichment
No data.
EUVD