PatchSiren

Bulutses Information Technologies CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Bulutses Information Technologies CVE published 2023-01-10

CVE-2022-4422

CVE-2022-4422 is a critical unauthenticated SQL injection vulnerability in Bulutses Information Technologies' Call Center System (Bulutdesk Callcenter) affecting all versions prior to 3.0. The vulnerability was published in the NVD on January 10, 2023, and carries a CVSS 3.1 score of 9.8 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The issue allows remote, unauthenticated attac [truncated]