7.5
CWE
89
Advisory Published
Updated

CVE-2023-48863: SQL Injection

First published: Mon Dec 04 2023(Updated: )

SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existing application to inject malicious SQL commands into the background database engine for execution, and sends some attack codes as commands or query statements to the interpreter. These malicious data can deceive the interpreter, so as to execute unplanned commands or unauthorized access to data.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Sem-cms Semcms=3.9

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2023-48863?

    CVE-2023-48863 is a vulnerability in SEMCMS 3.9 that allows an attacker to perform SQL Injection attacks.

  • What is the severity of CVE-2023-48863?

    The severity of CVE-2023-48863 is high with a CVSS score of 7.5.

  • How does CVE-2023-48863 work?

    CVE-2023-48863 allows an attacker to inject malicious SQL commands into the application's database engine to execute unauthorized actions.

  • How can I fix CVE-2023-48863?

    To fix CVE-2023-48863, it is recommended to update SEMCMS to a version that includes security checks on input to prevent SQL Injection attacks.

  • Where can I find more information about CVE-2023-48863?

    More information about CVE-2023-48863 can be found on the official SEMCMS website and the related Gitee page.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203