SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the shell_exect parameter to the \www\pages\matrix-gui-2.0 endpoint.
References
Link | Resource |
---|---|
https://github.com/varigit/matrix-gui-v2/issues/1 | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2023-03-08 08:15
Updated : 2023-03-14 08:34
NVD link : CVE-2023-26922
Mitre link : CVE-2023-26922
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
variscite
- matrix-gui