An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i_command.php.
History

Mon, 13 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i_command.php.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-01-13T00:00:00

Updated: 2025-01-13T21:56:55.654941

Reserved: 2023-09-08T00:00:00

Link: CVE-2023-42237

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-01-13T22:15:11.953

Modified: 2025-01-13T22:15:11.953

Link: CVE-2023-42237

cve-icon Redhat

No data.