---
id: CVE-2022-38615
title: >-
  SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection
  vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92
  parameters at /SVFE2/pages/feegroups/service_group.jsf.
summary: >-
  SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection
  vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92
  parameters at /SVFE2/pages/feegroups/service_group.jsf.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: bpcbt
product: smartvista_front-end
affected:
  - smartvista_front-end <= 2.2.22
published: '2022-09-09'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-38615'
references:
  - url: >-
      https://tf1t.gitbook.io/mycve/smartvista/smartvista-svfe2/sql-injection-in-service-group-feature-of-smartvista-svfe2-version-2.2.22-cve-2022-38615
    label: cve@mitre.org
  - url: 'http://bpcbt.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://smartvista.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://tf1t.gitbook.io/mycve/smartvista/smartvista-svfe2/sql-injection-in-service-group-feature-of-smartvista-svfe2-version-2.2.22-cve-2022-38615
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00903
epssPercentile: 0.58029
ingestedAt: '2026-07-06T17:03:25.183Z'
---

## Overview

SmartVista SVFE2 v2.2.22 was discovered to contain multiple SQL injection vulnerabilities via the UserForm:j_id88, UserForm:j_id90, and UserForm:j_id92 parameters at /SVFE2/pages/feegroups/service_group.jsf.

## Affected

- `smartvista_front-end <= 2.2.22`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
