Lucene search

K
cve[email protected]CVE-2023-4037
HistoryOct 04, 2023 - 12:15 p.m.

CVE-2023-4037

2023-10-0412:15:10
CWE-89
web.nvd.nist.gov
15
cve-2023-4037
blind sql injection
conacwin
web interface
local attacker
sensitive data
exploitation

9.9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

5.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter.

Affected configurations

Vulners
NVD
Node
setelsa_securityconacwinRange3.7.1.2

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "ConacWin",
    "vendor": "Setelsa Security",
    "versions": [
      {
        "status": "affected",
        "version": "3.7.1.2"
      }
    ]
  }
]

9.9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

5.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2023-4037