Vulnerabilities > Archerydms > Archery

DATE CVE VULNERABILITY TITLE RISK
2022-09-13 CVE-2022-38540 SQL Injection vulnerability in Archerydms Archery
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface.
network
low complexity
archerydms CWE-89
critical
9.8
2022-09-13 CVE-2022-38541 SQL Injection vulnerability in Archerydms Archery 1.8.3/1.8.4/1.8.5
Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface.
network
low complexity
archerydms CWE-89
critical
9.8
2022-09-13 CVE-2022-38542 SQL Injection vulnerability in Archerydms Archery
Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface.
network
low complexity
archerydms CWE-89
critical
9.8