{"id":"CVE-2022-21666","summary":" SQL Injection in useredit.php","details":"Useful Simple Open-Source CMS (USOC) is a content management system (CMS) for programmers. Versions prior to Pb2.4Bfx3 allowed Sql injection in usersearch.php only for users with administrative privileges. Users should replace the file `admin/pages/useredit.php` with a newer version. USOC version Pb2.4Bfx3 contains a fixed version of `admin/pages/useredit.php`.","aliases":["GHSA-557p-hhpc-4wrx"],"modified":"2026-08-27T03:30:53.436840214Z","published":"2022-01-10T20:00:12Z","database_specific":{"cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21666.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/Aaron-Junker/USOC/releases/tag/Pb2.4Bfx3"},{"type":"ADVISORY","url":"https://github.com/Aaron-Junker/USOC/security/advisories/GHSA-557p-hhpc-4wrx"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21666.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-21666"},{"type":"FIX","url":"https://github.com/Aaron-Junker/USOC/commit/c331d26aaab41a7e9e8c1c1a990132dca9d01e10"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/noraa-junker/USOC","events":[{"introduced":"0"},{"fixed":"c331d26aaab41a7e9e8c1c1a990132dca9d01e10"},{"fixed":"337ab4c04d270f1605c9ebcf7006b6aa97119755"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"Pb2.4Bfx3"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["Pb2.4Bfx2","Pb2.4Bfx1","Pb2.4Bfx0","Pb2.3Bfx0","Pb2.2Bfx0","Pb2.1Bfx0","Pb2.0Bfx1","Pb2.0Bfx0","Pb2.0Bfx0RCA","Pb1.8Bfx0","Pb1.7Bfx0","Pb1.4Bfx0","Pb1.6Bfx0","Pb1.3Bfx0","Pb1.2Bfx0","Pb1.1Bfx0","Pb1.0Bfx2","Pb1.0Bfx1,Pre-beta","Pb1.0Bfx1","Pb1.0Bfx0","Pa1.0Bfx0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-21666.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}