CVE-2023-4037
04.10.2023, 12:15
Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter.
Vendor | Product | Version |
---|---|---|
setelsa-security | conacwin | 3.7.1.2 |
𝑥
= Vulnerable software versions