A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application. Authenticated users can extract arbitrary information from the DBMS in an uncontrolled way.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published: 2023-08-09T08:01:57.279Z

Updated: 2024-08-02T10:07:06.613Z

Reserved: 2023-01-24T10:39:24.285Z

Link: CVE-2023-22378

cve-icon Vulnrichment

Updated: 2024-08-02T10:07:06.613Z

cve-icon NVD

Status : Modified

Published: 2023-08-09T09:15:13.507

Modified: 2024-05-28T13:15:08.783

Link: CVE-2023-22378

cve-icon Redhat

No data.