Thinking Software Technology Co., Ltd. Efence - SQL Injection
CVE-2023-22900
9.8CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 31 January 2023
What is CVE-2023-22900?
The Efence login function suffers from inadequate validation of user inputs, enabling unauthenticated remote attackers to exploit this flaw. This vulnerability permits attackers to inject arbitrary SQL commands, which can result in unauthorized access, modification, or deletion of the database. It is crucial for users of the Efence product to apply necessary security updates and implement proper input validation strategies to safeguard against potential exploits.
Affected Version(s)
Efence 1.2.58 DB.ver 28
