CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-24240

Critical · CVSS 9.8

ACEweb Online Portal — SQL Injection (CWE-89)

CVSS
9.8
nvd
EPSS
1.07%
61th pct
KEV
No
Class
other
CWE-89

Description

ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.

Search profile — drives PoC discovery

Symbols criteriashowschedule.awpshowschedule.awp
Keywords CVE-2022-24240ACEweb Online PortalACEwareSQL injectionshowschedule.awpcriteria parameter3.5.065
Versions: 3.5.065

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z