CVE-2023-22319: SQL Injection
A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a malicious packet to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22319?
CVE-2023-22319 is a SQL injection vulnerability that exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2.
How does CVE-2023-22319 affect Milesight VPN v2.0.2?
CVE-2023-22319 allows for authentication bypass in Milesight VPN v2.0.2 through a specially-crafted network request that triggers a SQL injection vulnerability.
What is the severity of CVE-2023-22319?
CVE-2023-22319 has a severity rating of 9.8 (critical).
How can an attacker exploit CVE-2023-22319?
An attacker can exploit CVE-2023-22319 by sending a malicious packet to the affected system, triggering the SQL injection vulnerability and bypassing authentication.
Is there a fix or patch available for CVE-2023-22319?
At the moment, there is no information available regarding a fix or patch for CVE-2023-22319. It is recommended to take precautionary measures, such as implementing strong network security controls and monitoring for any suspicious activity.