SUNNET WMPro - SQL Injection
CVE-2023-35851
7.5HIGH
What is CVE-2023-35851?
The SUNNET WMPro portal's FAQ function lacks proper validation for user input, allowing unauthenticated remote attackers to execute arbitrary SQL commands. This vulnerability can lead to unauthorized access to sensitive data stored in the database, posing significant security risks for organizations relying on this software.
Affected Version(s)
WMPro V5
