PT-2023-23422 · Microworld · Microworld Escan Management Console

Sahil Ojha

·

Published

2023-05-17

·

Updated

2025-01-22

·

CVE-2023-31702

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MicroWorld eScan Management Console version 14.0.1400.2281
Description The issue allows a remote attacker to perform SQL injection in the View User Profile feature, enabling them to dump the entire database and gain a Windows XP command shell. This can lead to code execution on the database server. The attack is carried out via the GetUserCurrentPwd endpoint with the UsrId parameter set to 1, specifically GetUserCurrentPwd?UsrId=1.
Recommendations For MicroWorld eScan Management Console version 14.0.1400.2281, consider disabling the GetUserCurrentPwd endpoint or restricting access to it until a patch is available. Avoid using the UsrId parameter in the affected endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-31702

Affected Products

Microworld Escan Management Console