ZeroHour

CVE-2023-48372

CVSS 3.1
9.8 critical
EPSS
1%p63
Published
()
Modified
Description

ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.

Vendors
itpison
Products
omicard edm
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.