CVE-2022-44015EPSS p64.2%
CVE-2022-44015CVE-2022-44015
simmeth / lieferantenmanager
Description
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary commands on the MSSQL server via the xp_cmdshell extended procedure.
Scoring
| CVSS | 9.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.17% probability of exploitation · percentile 64.2% · 2026-08-03T12:00:16Z |
| Last modified | 2026-06-17 |