Description
SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to obtain sensitive information via a database.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update the version to the latest or contact the SUNNET support team
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-39844 | SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to obtain sensitive information via a database. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7372-3994a-1.html |
|
History
Wed, 25 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-25T15:44:38.562Z
Reserved: 2023-06-19T02:28:47.605Z
Link: CVE-2023-35851
Updated: 2024-08-02T16:30:45.439Z
Status : Modified
Published: 2023-09-18T03:15:08.017
Modified: 2024-11-21T08:08:49.380
Link: CVE-2023-35851
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD