go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Thinking Software Technology Co., Ltd. Efence - SQL Injection

TVN ID TVN-202301001
CVE ID CVE-2023-22900
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Thinking Software Technology Co., Ltd. Efence 1.2.58 DB.ver 28
Description Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.
Solution Update Efence version to 1.2.58 DB.ver 29 (Aug. 2022)
Credit Kun Xian Lin (DEVCORE)
Public Date 2023-01-31
Top