.. / CVE-2022-24627

Exploit for AudioCodes Device Manager Express - SQL Injection (CVE-2022-24627)

Description:

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.

Nuclei Template

View the template here CVE-2022-24627.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-24627.yaml
Copy

References:

https://seclists.org/fulldisclosure/2023/Feb/12
https://nvd.nist.gov/vuln/detail/CVE-2022-24627
https://github.com/tr3ss/newclei