CVE Published: 05/09/2023 |
CVE Updated: 27/09/2024 |
CVE Year: 2023 Source: TR-CERT |
Vendor: Digita Information Technology |
Product: Smartrise Document Management System Status : PUBLISHED
CVE-2023-4034 Description
Improper Neutralization of Special Elements used in an SQL Command (\'SQL Injection\') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection.This issue affects Smartrise Document Management System: before Hvl-2.0.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* HIGH
Weakness Enumeration (CWE)
CWE-ID: CWE-89 CWE Name: CWE-89 Improper Neutralization of Special Elements used in an SQL Command (
SQL Injection
) Source: Digita Information Technology
Common Attack Pattern Enumeration and Classification (CAPEC)