CVE-2023-22324: SQL Injection
Published Jan 30, 2023
·Updated
SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtained.
Affected Software
1 affected component
Contec CONPROSYS HMI System<3.5.1
Remediation
Event History
Jan 30, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-22324?
CVE-2023-22324 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2023-22324?
To fix CVE-2023-22324, upgrade the CONPROSYS HMI System to version 3.5.1 or later.
3
Who is affected by CVE-2023-22324?
CVE-2023-22324 affects users of the CONPROSYS HMI System version 3.5.0 and earlier.
4
What can an attacker do with CVE-2023-22324?
An attacker can execute arbitrary SQL commands, potentially accessing sensitive information from the database.
5
Is CVE-2023-22324 a remote vulnerability?
Yes, CVE-2023-22324 allows a remote authenticated attacker to exploit the vulnerability.