Lucene search

K
cvelistTenableCVELIST:CVE-2023-3983
HistoryJul 31, 2023 - 12:00 a.m.

CVE-2023-3983

2023-07-3100:00:00
tenable
www.cve.org
1
authenticated
remote attacker
bypass checks
blind sql injection

9.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.4%

An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Advantech iView",
    "versions": [
      {
        "version": "versions prior to v5.7.4 build 6752",
        "status": "affected"
      }
    ]
  }
]

9.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.4%

Related for CVELIST:CVE-2023-3983