PT-2023-22454 · Medical Systems Co. · Medisys Weblab Products

Published

2023-05-11

·

Updated

2025-01-27

·

CVE-2023-29863

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Medical Systems Co. Medisys Weblab Products version 19.4.03
Description The issue is a SQL injection vulnerability that can be exploited via the tem:statement parameter in the WSDL files. This allows for potential unauthorized access to database information.
Recommendations For Medical Systems Co. Medisys Weblab Products version 19.4.03, consider restricting access to the tem:statement parameter in the WSDL files as a temporary workaround until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-29863

Affected Products

Medisys Weblab Products