Lucene search

K
nvd[email protected]NVD:CVE-2023-0953
HistoryMar 01, 2023 - 8:15 a.m.

CVE-2023-0953

2023-03-0108:15:11
CWE-89
web.nvd.nist.gov
1
input sanitization
devolutions server
sql injection
unauthorized access
system resources

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

35.4%

Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.

Affected configurations

Nvd
Node
devolutionsdevolutions_serverRange2022.3.12
VendorProductVersionCPE
devolutionsdevolutions_server*cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

35.4%

Related for NVD:CVE-2023-0953