CVE-2023-29154: SQL Injection
SQL injection vulnerability exists in the CONPROSYS HMI System (CHS) versions prior to 3.5.3. A user who can access the affected product with an administrative privilege may execute an arbitrary SQL command via specially crafted input to the query setting page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29154?
The severity of CVE-2023-29154 is considered critical due to the potential for unauthorized SQL command execution.
How do I fix CVE-2023-29154?
To fix CVE-2023-29154, update the CONPROSYS HMI System to version 3.5.3 or later.
Who is affected by CVE-2023-29154?
Users with administrative privileges accessing versions of CONPROSYS HMI System prior to 3.5.3 are affected by CVE-2023-29154.
What type of vulnerability is CVE-2023-29154?
CVE-2023-29154 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.
What can an attacker do exploiting CVE-2023-29154?
An attacker exploiting CVE-2023-29154 can execute unauthorized SQL commands on the database through specially crafted input.