CVE-2022-38541 Information

Description

Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface.

Reference

https://github.com/hhyo/Archery/blob/v1.8.5/sql/urls.py#L136 https://github.com/hhyo/Archery/blob/v1.8.5/sql/urls.py#L136

Share on: