Description
Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter.
No analysis available yet.
Remediation
Vendor Solution
Setelsa Security has released version 3.9.1.1, which resolves the reported vulnerability.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-53929 | Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter. |
References
History
Thu, 19 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-19T19:21:21.060Z
Reserved: 2023-08-01T08:30:55.968Z
Link: CVE-2023-4037
Updated: 2024-08-02T07:17:12.026Z
Status : Modified
Published: 2023-10-04T12:15:10.733
Modified: 2024-11-21T08:34:16.473
Link: CVE-2023-4037
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD