CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-38619

Critical · CVSS 9.8

SmartVista SVFE2 — SQL Injection

CVSS
9.8
nvd
EPSS
0.94%
57th pct
KEV
No
Class
other
CWE-89, CWE-89

Description

SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.

Search profile — drives PoC discovery

Symbols UserForm:j_id90/SVFE2/pages/feegroups/mcc_group.jsfj_id90mcc_group.jsffeegroups
Keywords CVE-2022-38619SmartVista SVFE2SQL injectionmcc_groupSVFE2 SQLiSmartVista SQLiUserForm j_id90feegroups mcc_groupSVFE2 2.2.22BPC SmartVista
Versions: 2.2.22

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z