CVE-2022-24240
Critical · CVSS 9.8ACEweb Online Portal — SQL Injection (CWE-89)
- CVSS
- 9.8
- nvd
- EPSS
- 1.07%
- 61th pct
- KEV
- No
- Class
- other
- CWE-89
Description
ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.
Search profile — drives PoC discovery
Symbols criteriashowschedule.awpshowschedule.awp
Keywords CVE-2022-24240ACEweb Online PortalACEwareSQL injectionshowschedule.awpcriteria parameter3.5.065
Versions: 3.5.065
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z