← Back to CVE List

CVE-2022-44015

Published: 2022-12-25T05:15Z
Last Modified: 2025-04-15T14:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary commands on the MSSQL server via the xp_cmdshell extended procedure. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt