← Vulnerability feed

Vulnerability record · CVE-2022-48602 · published 9 August 2023

CVE-2022-48602: Sciencelogic sl1 os command injection vulnerability

Sciencelogic · Sl1

A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

8.8 CVSS 3.1 High EPSS 0.73% · top 47.4% CWE-78 · OS command injectionCWE-89 · SQL injection
8.8CVSS 3.1 base score
0.73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-48602 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2024-9537ScienceLogic SL1 third-party component flaw allows unauthenticated remote compromiseScienceLogic SL1 (formerly EM7) contains an unspecified vulnerability in an unspecified third-party component packaged with the product. The flaw is …KEVEPSS 3.8%analysed8.8CVE-2022-48601Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and p…EPSS 0.73%8.8CVE-2022-48603Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and …EPSS 0.73%8.8CVE-2022-48604Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes …EPSS 0.73%8.8CVE-2022-48592Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes unsaniti…EPSS 0.73%8.8CVE-2022-48593Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the “topology data service” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and …EPSS 0.72%8.8CVE-2022-48594Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the “ticket watchers email” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and …EPSS 0.73%8.8CVE-2022-48595Sciencelogic sl1 os command injection vulnerabilityA SQL injection vulnerability exists in the “ticket template watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input a…EPSS 0.73%

Source: NIST National Vulnerability Database (record CVE-2022-48602), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.