CVE-2023-46509: Code Injection
Published Oct 27, 2023
·Updated
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.
Affected Software
2 affected components
All of the following
Contec Solarview Compact Firmware<=6.0
Contec SolarView Compact
Event History
Oct 27, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-46509?
The severity of CVE-2023-46509 is critical with a CVSS score of 9.8.
2
What is the affected software of CVE-2023-46509?
Contec SolarView Compact v.6.0 and earlier versions are affected by CVE-2023-46509.
3
How can an attacker exploit CVE-2023-46509?
An attacker can exploit CVE-2023-46509 by executing arbitrary code via the texteditor.php component.
4
Is Contec SolarView Compact vulnerable to CVE-2023-46509?
No, Contec SolarView Compact is not vulnerable to CVE-2023-46509.
5
How can I fix CVE-2023-46509?
To fix CVE-2023-46509, it is recommended to update Contec SolarView Compact to a version higher than 6.0.