Lucene search

K
cveMitreCVE-2023-26856
HistoryApr 05, 2023 - 2:15 p.m.

CVE-2023-26856

2023-04-0514:15:07
CWE-89
mitre
web.nvd.nist.gov
50
cve-2023-26856
dynamic transaction queuing system
sql injection
admin
ajax
login

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

31.1%

Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/ajax.php?action=login.

Affected configurations

Nvd
Node
dynamic_transaction_queuing_system_projectdynamic_transaction_queuing_systemMatch1.0
VendorProductVersionCPE
dynamic_transaction_queuing_system_projectdynamic_transaction_queuing_system1.0cpe:2.3:a:dynamic_transaction_queuing_system_project:dynamic_transaction_queuing_system:1.0:*:*:*:*:*:*:*

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

31.1%

Related for CVE-2023-26856