CVE-2023-33367: SQL Injection
A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-33367?
CVE-2023-33367 is a SQL injection vulnerability in Control ID IDSecure 4.7.26.0 and prior versions, which allows unauthenticated attackers to write PHP files on the server's root directory, resulting in remote code execution.
How severe is CVE-2023-33367?
CVE-2023-33367 has a severity rating of 9.8, which is considered critical.
What can an attacker do with CVE-2023-33367?
With CVE-2023-33367, an attacker can write PHP files on the server's root directory, enabling them to execute remote code.
What software versions are affected by CVE-2023-33367?
CVE-2023-33367 affects Control ID IDSecure versions up to and including 4.7.26.0.
How can I fix CVE-2023-33367?
To fix CVE-2023-33367, update Control ID IDSecure to a version higher than 4.7.26.0.