CVE ID: CVE-2022-47523
Severity: High
Update Released Build: 10.1.2228.19
Update Released Date: January 07, 2023
An authenticated SQL injection vulnerability in Endpoint Central MSP (CVE-2022-47523) was identified which may allow an adversary to execute custom queries and access the database table entries. This has now been fixed by enhancing validation and escaping special characters.
Upgrading to the latest version is strongly advised due to this vulnerability's severity. To upgrade, follow the steps below:
nextheia.com via ManageEngine's Bug Bounty program.
For any further queries on this, please reach out to Endpoint Central MSP support at msp-endpointcentral-support@manageengine.com.