📦 Sl1

by Sciencelogic

🔍 What is Sl1?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-9537

CRITICAL CVSS 9.8 Oct 18, 2024

This CVE describes a critical vulnerability in ScienceLogic SL1's third-party component that allows remote code execution. The vulnerability affects all SL1 versions before 12.1.3, 12.2.3, and 12.3, w...

CVE-2022-48602

HIGH CVSS 8.8 Aug 9, 2023

This SQL injection vulnerability in ScienceLogic SL1's message viewer print feature allows attackers to execute arbitrary SQL commands by injecting malicious input. It affects organizations using vuln...

CVE-2022-48604

HIGH CVSS 8.8 Aug 9, 2023

This SQL injection vulnerability in ScienceLogic SL1's logging export feature allows attackers to execute arbitrary SQL commands against the database by injecting malicious input. It affects ScienceLo...

CVE-2022-48592

HIGH CVSS 8.8 Aug 9, 2023

This SQL injection vulnerability in ScienceLogic SL1 allows attackers to execute arbitrary SQL commands through the vendor_country parameter in the vendor print report feature. This could lead to data...

CVE-2022-48594

HIGH CVSS 8.8 Aug 9, 2023

This SQL injection vulnerability in ScienceLogic SL1's ticket watchers email feature allows attackers to execute arbitrary SQL commands by injecting malicious input. Attackers could potentially read, ...

CVE-2022-48596

HIGH CVSS 8.8 Aug 9, 2023

This SQL injection vulnerability in ScienceLogic SL1's ticket queue watchers feature allows attackers to execute arbitrary SQL commands against the database by injecting malicious input. Organizations...

CVE-2022-48598

HIGH CVSS 8.8 Aug 9, 2023

This SQL injection vulnerability in ScienceLogic SL1 allows attackers to execute arbitrary SQL commands through the 'reporter events type date' feature. Attackers could read, modify, or delete databas...

CVE-2022-48600

HIGH CVSS 8.8 Aug 9, 2023

This SQL injection vulnerability in ScienceLogic SL1's notes view feature allows attackers to execute arbitrary SQL commands by injecting malicious input. It affects ScienceLogic SL1 users who have th...

CVE-2022-48588

HIGH CVSS 8.8 Aug 9, 2023

This SQL injection vulnerability in ScienceLogic SL1's schedule editor feature allows attackers to execute arbitrary SQL commands against the database by injecting malicious input. It affects organiza...

CVE-2022-48590

HIGH CVSS 8.8 Aug 9, 2023

This SQL injection vulnerability in ScienceLogic SL1 allows attackers to execute arbitrary SQL commands through the admin dynamic app mib errors feature. Attackers could potentially access, modify, or...

CVE-2022-48582

HIGH CVSS 8.8 Aug 9, 2023

This CVE describes a command injection vulnerability in ScienceLogic SL1's ticket report generation feature. Attackers can inject arbitrary commands into the underlying operating system by providing m...

CVE-2022-48584

HIGH CVSS 8.8 Aug 9, 2023

This CVE describes a command injection vulnerability in ScienceLogic SL1's report download/convert feature where unsanitized user input is passed directly to shell commands. Attackers can execute arbi...

CVE-2022-48586

HIGH CVSS 8.8 Aug 9, 2023

This SQL injection vulnerability in ScienceLogic SL1's 'json walker' feature allows attackers to inject malicious SQL queries through unsanitized user input. Successful exploitation could lead to data...

CVE-2022-48580

HIGH CVSS 8.8 Aug 9, 2023

This CVE describes a command injection vulnerability in ScienceLogic SL1's ARP ping device tool that allows attackers to execute arbitrary commands on the underlying operating system. Organizations us...