ZeroHour

CVE-2023-33367

CVSS 3.1
9.8 critical
EPSS
1%p63
Published
()
Modified
Description

A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in remote code execution.

Vendors
assaabloy
Products
control id idsecure
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.