PT-2025-1469 · Selesta · Selesta Visual Access Manager

Published

2025-01-13

·

Updated

2025-01-14

·

CVE-2023-42243

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Selesta Visual Access Manager versions prior to 4.42.2
Description The issue allows an authenticated user to access the administrative page "/common/vam Sql.php", which permits arbitrary SQL queries. This can be exploited by sending queries to the vam Sql.php page, potentially allowing unauthorized data access or modification.
Recommendations For versions prior to 4.42.2, update to version 4.42.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/common/vam Sql.php" page to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-42243

Affected Products

Selesta Visual Access Manager