A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in remote code execution.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-37530 | A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in remote code execution. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 17 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-17T14:48:32.915Z
Reserved: 2023-05-22T00:00:00
Link: CVE-2023-33367
Updated: 2024-08-02T15:47:05.040Z
Status : Modified
Published: 2023-08-05T02:15:10.763
Modified: 2024-11-21T08:05:28.950
Link: CVE-2023-33367
No data.
OpenCVE Enrichment
No data.
EUVD