Remote Code Execution Vulnerability in Voltronic Power ViewPower Pro
CVE-2023-51586
9.8CRITICAL
What is CVE-2023-51586?
A vulnerability exists in Voltronic Power's ViewPower Pro that allows remote attackers to execute arbitrary code without authentication. The flaw is found in the selectEventConfig method, where a lack of proper validation for user-supplied strings leads to unsafe SQL query constructions. This vulnerability enables attackers to run code in the context of the LOCAL SERVICE, posing a significant risk to affected installations.
Affected Version(s)
ViewPower Pro 2.0-22165
