CVE detail
CVE-2020-22669 — CVE-2020-22669
Published 2022-09-02 · Modified 2026-06-17 · Vendor owasp · Product owasp_modsecurity_core_rule_set · Source nvd
CRITICAL
severity
CVSS-derived band
0.0103
EPSS probability
exploitation probability, 30d
61.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References