CVE-2023-31847
EUVD-2023-3613717.05.2023, 01:15
In davinci 0.3.0-rc after logging in, the user can connect to the mysql malicious server by controlling the data source to read arbitrary files on the client side.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| davinci_project | davinci | 0.3.0:rc |
𝑥
= Vulnerable software versions