PT-2023-22454 · Medical Systems Co. · Medisys Weblab Products

Publicado

2023-05-11

·

Atualizado

2025-01-27

·

CVE-2023-29863

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Medical Systems Co. Medisys Weblab Products version 19.4.03
Description The issue is a SQL injection vulnerability that can be exploited via the tem:statement parameter in the WSDL files. This allows for potential unauthorized access to database information.
Recommendations For Medical Systems Co. Medisys Weblab Products version 19.4.03, consider restricting access to the tem:statement parameter in the WSDL files as a temporary workaround until a patch is available.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-29863

Produtos afetados

Medisys Weblab Products