CVE-2023-33967: EaseProbe vulnerable to SQL injection when using MySQL/PostgreSQL data checking
Published May 31, 2023
·Updated
EaseProbe is a tool that can do health/status checking. An SQL injection issue was discovered in EaseProbe before 2.1.0 when using MySQL/PostgreSQL data checking. This problem has been fixed in v2.1.0.
Affected Software
1 affected component
Megaease Easeprobe<2.1.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EaseProbeto a version that resolves this vulnerability.Fixed in 2.1.0
Event History
May 31, 2023
CVE Published
via MITRE·05:18 PM
Data Sourced
via MITRE·05:18 PM
DescriptionSeverityWeakness
Data Sourced
06:15 PM
Description
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-33967?
The severity of CVE-2023-33967 is classified as high due to the potential for SQL injection attacks.
2
How do I fix CVE-2023-33967?
To fix CVE-2023-33967, update EaseProbe to version 2.1.0 or later.
3
What products are affected by CVE-2023-33967?
CVE-2023-33967 affects EaseProbe versions prior to 2.1.0.
4
Can CVE-2023-33967 lead to data breaches?
Yes, CVE-2023-33967 can lead to data breaches if exploited, as it allows for unauthorized access to the database.
5
What type of vulnerability is CVE-2023-33967?
CVE-2023-33967 is an SQL injection vulnerability.