{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2022-39303","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","dateUpdated":"2025-04-23T16:50:08.452Z","dateReserved":"2022-09-02T00:00:00.000Z","datePublished":"2022-10-13T00:00:00.000Z"},"containers":{"cna":{"title":"Ree6 vulnerable to SQL Injection","providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2022-10-13T00:00:00.000Z"},"descriptions":[{"lang":"en","value":"Ree6 is a moderation bot. This vulnerability allows manipulation of SQL queries. This issue has been patched in version 1.7.0 by using Javas PreparedStatements, which allow object setting without the risk of SQL injection. There are currently no known workarounds."}],"affected":[{"vendor":"Ree6-Applications","product":"Ree6","versions":[{"version":"<= 1.6.4","status":"affected"}]}],"references":[{"url":"https://github.com/Ree6-Applications/Ree6/security/advisories/GHSA-69xv-xjfw-4pv8"},{"url":"https://github.com/Ree6-Applications/Ree6/compare/1.6.4...1.7."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}],"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","description":"CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","cweId":"CWE-89"}]}],"source":{"advisory":"GHSA-69xv-xjfw-4pv8","discovery":"UNKNOWN"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T12:00:44.000Z"},"title":"CVE Program Container","references":[{"url":"https://github.com/Ree6-Applications/Ree6/security/advisories/GHSA-69xv-xjfw-4pv8","tags":["x_transferred"]},{"url":"https://github.com/Ree6-Applications/Ree6/compare/1.6.4...1.7.","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-04-23T15:47:48.310718Z","id":"CVE-2022-39303","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-04-23T16:50:08.452Z"}}]}}