First published: Mon Jan 13 2025(Updated: )
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple parameters of /monitor/s_normalizedtrans.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Selesta Visual Access Manager | <4.42.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-42235 has not been explicitly rated, but SQL Injection vulnerabilities are generally considered critical due to their potential impact.
To fix CVE-2023-42235, update Selesta Visual Access Manager to version 4.42.2 or later.
CVE-2023-42235 allows an authenticated attacker to perform SQL Injection through multiple parameters in the affected software.
Selesta Visual Access Manager versions prior to 4.42.2 are affected by CVE-2023-42235.
Yes, an attacker must be authenticated to exploit CVE-2023-42235 and perform SQL Injection.