### [CVE-2022-38118](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38118) ![](https://img.shields.io/static/v1?label=Product&message=OAKlouds&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3C%3D%20OAKlouds-mol_metting-2.0-163%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-89%20SQL%20Injection&color=brighgreen) ### Description OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user privilege can perform SQL-injection to access, modify, delete database, perform system operations and disrupt service. ### POC #### Reference No PoCs from references. #### Github - https://github.com/karimhabush/cyberowl