Lucene search

K
cvelistINCIBECVELIST:CVE-2023-4037
HistoryOct 04, 2023 - 11:05 a.m.

CVE-2023-4037 SQL injection in Setelsa Security ConacWin

2023-10-0411:05:05
CWE-89
INCIBE
www.cve.org
sql injection
conacwin
web interface
local attacker
sensitive data

9.9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

9.4 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "ConacWin",
    "vendor": "Setelsa Security",
    "versions": [
      {
        "status": "affected",
        "version": "3.7.1.2"
      }
    ]
  }
]

9.9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

9.4 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVELIST:CVE-2023-4037