Aller au contenu

Fiche vulnérabilité

CVE-2023-26440 : faille élevée OX Software GmbH OX App Suite (CVSS 7.1)

Description

The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized and would later be executed when creating new cache groups. Attackers with access to a local or restricted network could perform arbitrary SQL queries. We have improved the input check for API calls and filter for potentially malicious content. No publicly available exploits are known.

En bref

Sévérité
Élevée (CVSS 7.1)
Vecteur CVSS
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
2 août 2023
Dernière mise à jour
2 août 2024

Produits concernés

  • OX Software GmbH OX App Suite

Références

Rechercher une autre vulnérabilité dans la base CVE