CVE-2023-7299: DataGear resolveSql sql injection
A vulnerability was found in DataGear up to 4.60. It has been declared as critical. This vulnerability affects unknown code of the file /dataSet/resolveSql. The manipulation of the argument sql leads to sql injection. The attack can be initiated remotely. Upgrading to version 4.7.0 is able to address this issue. It is recommended to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DataGearto a version that resolves this vulnerability.Fixed in 4.7.0
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7299?
CVE-2023-7299 has been declared as critical.
How do I fix CVE-2023-7299?
To remediate CVE-2023-7299, upgrade DataGear to version 4.7.0 or later.
What type of vulnerability is CVE-2023-7299?
CVE-2023-7299 is an SQL injection vulnerability.
Can CVE-2023-7299 be exploited remotely?
Yes, the attack associated with CVE-2023-7299 can be initiated remotely.
Which versions of DataGear are affected by CVE-2023-7299?
DataGear versions up to and including 4.60 are affected by CVE-2023-7299.