CVE-2023-41262
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Oct 12, 2023
Updated: Oct 16, 2023
CWE ID 89
Summary
CVE-2023-41262 is a newly discovered vulnerability affecting Plixer Scrutinizer versions prior to 19.3.1. The issue lies in the /fcgi/scrut_fcgi.fcgi file, specifically in the csvExportReport endpoint action's generateCSV function. An SQL injection vulnerability exists, which can be exploited by an unauthenticated user through manipulating the sorting parameter. Successful exploitation grants the attacker the ability to execute arbitrary SQL statements on the application's backend database server.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Plixer Scrutinizer
Affected Vendors
- Plixer International