An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV is vulnerable to SQL injection through the sorting parameter, allowing an unauthenticated user to execute arbitrary SQL statements in the context of the application's backend database server.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Sep 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-10-12T00:00:00
Updated: 2024-09-18T18:37:46.135Z
Reserved: 2023-08-25T00:00:00
Link: CVE-2023-41262
Vulnrichment
Updated: 2024-08-02T18:54:05.096Z
NVD
Status : Modified
Published: 2023-10-12T23:15:11.190
Modified: 2024-11-21T08:20:56.430
Link: CVE-2023-41262
Redhat
No data.