CVE-2023-39853
PoC —CVSS 3.1
6.5 medium
EPSS
<1%p53
Published
()
Modified
Description
SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the doobj and doevent parameters in the Network Disk backend module.
- Vendors
- dzzoffice
- Products
- dzzoffice
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.