PT-2024-13382 · Epmm · Epmm

Published

2024-03-14

·

Updated

2025-06-13

·

CVE-2023-46806

CVSS v3.1

6.7

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions EPMM versions prior to 12.1.0.0
Description An SQL Injection issue in a web component of EPMM allows an authenticated user with appropriate privilege to access or modify data in the underlying database.
Recommendations For versions prior to 12.1.0.0, update to version 12.1.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the web component to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2023-46806

Affected Products

Epmm