CVE-2023-37513
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Aug 11, 2023
Updated: Aug 17, 2023
Summary
CVE-2023-39806 is a newly disclosed vulnerability affecting iCMS version 7.0.16. This issue involves a SQL injection vulnerability that can be exploited through the bakupdata function. An attacker can manipulate input data to inject malicious SQL commands, potentially gaining unauthorized access to sensitive information or even taking control of the system. The vulnerability poses a significant risk to organizations using iCMS, making it essential for them to apply the necessary patches as soon as possible to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- HCL Technologies Ltd.