Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12.
History

Wed, 18 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published: 2023-10-10T17:27:25.515Z

Updated: 2024-09-18T18:52:15.809Z

Reserved: 2023-08-11T16:23:07.566Z

Link: CVE-2023-4309

cve-icon Vulnrichment

Updated: 2024-08-02T07:24:04.378Z

cve-icon NVD

Status : Modified

Published: 2023-10-10T18:15:19.173

Modified: 2024-08-02T08:15:19.200

Link: CVE-2023-4309

cve-icon Redhat

No data.