First published: Mon Jan 13 2025(Updated: )
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i_command.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Selesta Visual Access Manager | <4.42.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42237 is classified as a critical vulnerability due to its potential impact on the security of the database.
To mitigate CVE-2023-42237, upgrade Selesta Visual Access Manager to version 4.42.2 or later.
CVE-2023-42237 affects all users of Selesta Visual Access Manager versions prior to 4.42.2.
CVE-2023-42237 is categorized as an SQL Injection vulnerability.
An authenticated attacker can exploit CVE-2023-42237 to execute arbitrary SQL queries through multiple GET parameters.