go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

ELITE Web Fax - SQL Injection

TVN ID TVN-202305003
CVE ID CVE-2023-28701
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Contact tech support from ELITE
Description ELITE TECHNOLOGY CORP. Web Fax has a vulnerability of SQL Injection. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to perform arbitrary system commands, disrupt service or terminate service.
Solution 3/29 Release
Credit Huang Yu Ze (CHT Security)
Public Date 2023-05-30
Top