CVE Published: 10/10/2023 |
CVE Updated: 18/09/2024 |
CVE Year: 2023 Source: cisa-cg |
Vendor: Election Services Co. (ESC) |
Product: Internet Election Service Status : PUBLISHED
CVE-2023-4309 Description
Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12.
Metrics
CVSS Version: 3.1 |
Base Score: 10 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* HIGH
Weakness Enumeration (CWE)
CWE-ID: CWE-89 CWE Name: CWE-89 Improper Neutralization of Special Elements used in an SQL Command (
SQL Injection
) Source: Election Services Co. (ESC)
Common Attack Pattern Enumeration and Classification (CAPEC)