First published: Tue Nov 28 2023(Updated: )
SQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be exploited with a low privileged account.
Credit: psirt@solarwinds.com
Affected Software | Affected Version | How to fix |
---|---|---|
Solarwinds Solarwinds Platform | <2023.4.2 |
All SolarWinds Platform customers are advised to upgrade to the latest version of the SolarWinds Platform version 2023.4.2
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40056 is a SQL Injection Remote Code Execution vulnerability found in the SolarWinds Platform.
CVE-2023-40056 has a severity value of 8, which is considered high.
Any SolarWinds Platform user with a low privileged account is affected by CVE-2023-40056.
CVE-2023-40056 can be exploited through SQL Injection with a low privileged account.
To fix CVE-2023-40056, apply the necessary updates and patches provided by SolarWinds.