CVE-2022-24407 | Cyrus SASL up to 2.1.27 UPDATE Statement plugins/sql.c Password escape output (EUVD-2022-29299)
A vulnerability was found in Cyrus SASL up to 2.1.27 and classified as critical. This affects an unknown function of the file plugins/sql.c of the component UPDATE Statement Handler. The manipulation of the argument Password results in escaping of output.
This vulnerability is identified as CVE-2022-24407. The attack can only be performed from the local network. There is not any exploit available.
It is suggested to upgrade the affected component.