Control iD RHiD Edit a sql injection
CVE-2023-2043

9.8CRITICAL

Key Information:

Vendor

Control iD

Status
Vendor
CVE Published:
14 April 2023

What is CVE-2023-2043?

A significant vulnerability exists in Control iD RHiD version 23.3.19.0, where improper validation of user-supplied data in the email input field of the Edit Handler component can be exploited to perform SQL injection attacks. This flaw allows an attacker to craft malicious inputs that may compromise the confidentiality and integrity of the database through remote exploitation. As this vulnerability goes unaddressed, systems utilizing this version could be at risk of unauthorized data access and manipulation.

Affected Version(s)

RHiD 23.3.19.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stux (VulDB User)
.