Aller au contenu

Fiche vulnérabilité

CVE-2023-41262 : faille critique plixer scrutinizer (CVSS 9.8)

Description

An issue was discovered in /fcgi/scrut_fcgi.fcgi in Plixer Scrutinizer before 19.3.1. The csvExportReport endpoint action generateCSV is vulnerable to SQL injection through the sorting parameter, allowing an unauthenticated user to execute arbitrary SQL statements in the context of the application's backend database server.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
12 oct. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • plixer scrutinizer

Références

Rechercher une autre vulnérabilité dans la base CVE