Thinking Software Technology Co., Ltd. Efence - SQL Injection
CVE-2023-22900

9.8CRITICAL

What is CVE-2023-22900?

The Efence login function suffers from inadequate validation of user inputs, enabling unauthenticated remote attackers to exploit this flaw. This vulnerability permits attackers to inject arbitrary SQL commands, which can result in unauthorized access, modification, or deletion of the database. It is crucial for users of the Efence product to apply necessary security updates and implement proper input validation strategies to safeguard against potential exploits.

Affected Version(s)

Efence 1.2.58 DB.ver 28

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DEVCORE
.