CVE-2023-22275: ZDI-CAN-21306: Adobe RoboHelp Server GetNewUserId SQL Injection Information Disclosure Vulnerability
Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to information disclosure by an unauthenticated attacker. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22275?
CVE-2023-22275 is an SQL Injection vulnerability in Adobe RoboHelp Server that could lead to information disclosure by an unauthenticated attacker.
How does CVE-2023-22275 affect Adobe RoboHelp Server?
CVE-2023-22275 affects Adobe RoboHelp Server versions 11.4 and earlier.
What is the severity of CVE-2023-22275?
The severity of CVE-2023-22275 is high with a CVSS score of 7.5.
How can an attacker exploit CVE-2023-22275?
An attacker can exploit CVE-2023-22275 by injecting malicious SQL commands to retrieve sensitive information from the server.
Is user interaction required to exploit CVE-2023-22275?
No, user interaction is not required to exploit CVE-2023-22275.
How can I fix CVE-2023-22275?
To fix CVE-2023-22275, update Adobe RoboHelp Server to version 11.4.1 or later.