CVE Published: 23/05/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: TR-CERT |
Vendor: Adam Retail Automation Systems |
Product: Mobilmen Terminal Software Status : PUBLISHED
CVE-2023-1508 Description
Improper Neutralization of Special Elements used in an SQL Command (\'SQL Injection\') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection.This issue affects Mobilmen Terminal Software: before 3.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* HIGH
Weakness Enumeration (CWE)
CWE-ID: CWE-89 CWE Name: CWE-89 Improper Neutralization of Special Elements used in an SQL Command (
SQL Injection
) Source: Adam Retail Automation Systems
Common Attack Pattern Enumeration and Classification (CAPEC)