CVE Published: 14/04/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: TR-CERT |
Vendor: Eskom |
Product: Water Metering Software Status : PUBLISHED
CVE-2023-1863 Description
Improper Neutralization of Special Elements used in an SQL Command (\'SQL Injection\') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection.This issue affects Water Metering Software: before 23.04.06.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H