First published: Mon Jul 31 2023(Updated: )
An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection.
Credit: vulnreport@tenable.com vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech iView | <5.7.4.6752 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3983 is an authenticated SQL injection vulnerability in Advantech iView versions prior to v5.7.4 build 6752.
The severity of CVE-2023-3983 is high with a CVSS score of 8.8.
CVE-2023-3983 allows authenticated remote attackers to bypass checks and perform blind SQL injection in Advantech iView.
To fix CVE-2023-3983, users should update Advantech iView to version 5.7.4 build 6752 or above.
You can find more information about CVE-2023-3983 at the following link: https://www.tenable.com/security/research/tra-2023-24