{"id":"CVE-2022-21644","summary":" SQL Injection via search in USOC","details":"USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch.php. In search terms provided by the user were not sanitized and were used directly to construct a sql statement. The only users permitted to search are site admins. Users are advised to upgrade as soon as possible. There are not workarounds for this issue.","aliases":["GHSA-89jg-6fr3-9q4h"],"modified":"2026-08-12T03:51:45.860623931Z","published":"2022-01-04T20:00:12Z","database_specific":{"cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21644.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/Aaron-Junker/USOC/security/advisories/GHSA-89jg-6fr3-9q4h"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21644.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-21644"},{"type":"FIX","url":"https://github.com/Aaron-Junker/USOC/commit/06217c66c8f9b114726b21633eabcd88ac9034aa"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/noraa-junker/USOC","events":[{"introduced":"0"},{"fixed":"06217c66c8f9b114726b21633eabcd88ac9034aa"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"Pb2.4Bfx2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["Pb2.4Bfx1","Pb2.4Bfx0","Pb2.3Bfx0","Pb2.2Bfx0","Pb2.1Bfx0","Pb2.0Bfx1","Pb2.0Bfx0","Pb2.0Bfx0RCA","Pb1.8Bfx0","Pb1.7Bfx0","Pb1.4Bfx0","Pb1.6Bfx0","Pb1.3Bfx0","Pb1.2Bfx0","Pb1.1Bfx0","Pb1.0Bfx2","Pb1.0Bfx1,Pre-beta","Pb1.0Bfx1","Pb1.0Bfx0","Pa1.0Bfx0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-21644.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}