SQL Injection Vulnerability in Documize by Documize Inc.
CVE-2023-23634
9.8CRITICAL
What is CVE-2023-23634?
An SQL Injection vulnerability exists in Documize version 5.4.2, allowing remote attackers to execute arbitrary code by manipulating the 'user' parameter in the /api/dashboard/activity endpoint. This weakness can lead to unauthorized access and potential compromise of the application's database integrity.
