SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to obtain sensitive information via a database.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the version to the latest or contact the SUNNET support team
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-39844 | SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to obtain sensitive information via a database. |
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7372-3994a-1.html |
|
Wed, 25 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-25T15:44:38.562Z
Reserved: 2023-06-19T02:28:47.605Z
Link: CVE-2023-35851
Updated: 2024-08-02T16:30:45.439Z
Status : Modified
Published: 2023-09-18T03:15:08.017
Modified: 2026-06-17T06:05:20.287
Link: CVE-2023-35851
No data.
OpenCVE Enrichment
No data.
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
EUVD