SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may execute an arbitrary SQL command via specially crafted input to the query setting page.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 09 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-01-09T19:24:43.251Z
Reserved: 2023-05-11T00:00:00
Link: CVE-2023-29154
Updated: 2024-08-02T14:00:15.588Z
Status : Modified
Published: 2023-06-01T02:15:09.760
Modified: 2025-01-09T20:15:33.140
Link: CVE-2023-29154
No data.
OpenCVE Enrichment
No data.
Weaknesses