Lucene search

K
nvd[email protected]NVD:CVE-2023-2046
HistoryJul 10, 2023 - 4:15 p.m.

CVE-2023-2046

2023-07-1016:15:50
CWE-89
web.nvd.nist.gov
2
cve-2023-2046
sql injection
yontem informatics
vehicle tracking system
security vulnerability
cve

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.001

Percentile

36.7%

Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Yontem Informatics Vehicle Tracking System allows SQL Injection.This issue affects Vehicle Tracking System: before 8.

Affected configurations

Nvd
Node
yontemizlemevehicle_tracking_systemRange<8.0
VendorProductVersionCPE
yontemizlemevehicle_tracking_system*cpe:2.3:a:yontemizleme:vehicle_tracking_system:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.001

Percentile

36.7%

Related for NVD:CVE-2023-2046