CVE-2023-4661: SQLi in Saphira Connect
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saphira Saphira Connect allows SQL Injection.
This issue affects Saphira Connect: before 9.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saphira Saphira Connect allows SQL Injection.This issue affects Saphira Connect: before 9.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-4661.
What is the severity of CVE-2023-4661?
The severity of CVE-2023-4661 is critical with a CVSS score of 9.8.
What is the affected software for CVE-2023-4661?
The affected software for CVE-2023-4661 is Saphira Connect version up to and exclusive of 9.0.
What is the CWE category for CVE-2023-4661?
The CWE category for CVE-2023-4661 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).
How do I fix the SQL Injection vulnerability in Saphira Connect?
To fix the SQL Injection vulnerability in Saphira Connect, update to version 9.0 or later.