Lucene search

K
cvelistMitreCVELIST:CVE-2023-47261
HistoryDec 14, 2023 - 12:00 a.m.

CVE-2023-47261

2023-12-1400:00:00
mitre
www.cve.org
4
cve-2023-47261
dokmee ecm
remote code execution
sql injection
sql server database access
xp_cmdshell enabled

AI Score

10

Confidence

High

EPSS

0.003

Percentile

70.5%

Dokmee ECM 7.4.6 allows remote code execution because the response to a GettingStarted/SaveSQLConnectionAsync /#/gettingstarted request contains a connection string for privileged SQL Server database access, and xp_cmdshell can be enabled.

AI Score

10

Confidence

High

EPSS

0.003

Percentile

70.5%

Related for CVELIST:CVE-2023-47261