CVE-2023-0953: SQL Injection
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Devolutions Server vulnerability?
The vulnerability ID for this Devolutions Server vulnerability is CVE-2023-0953.
What is the title of this Devolutions Server vulnerability?
The title of this Devolutions Server vulnerability is 'Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier'.
What is the impact of this Devolutions Server vulnerability?
This Devolutions Server vulnerability allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.
What is the severity of CVE-2023-0953?
The severity of CVE-2023-0953 is high with a CVSS score of 8.8.
How do I fix the CVE-2023-0953 vulnerability in Devolutions Server?
To fix the CVE-2023-0953 vulnerability in Devolutions Server, update to version 2022.3.13 or later which addresses the insufficient input sanitization issue.