Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-34210: ZUSO Generation 如梭世代

SQL Injection in create customer group function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to execute arbitrary SQL commands via the ctl00$ContentPlaceHolder1$txtCustSQL parameter.

CVE
#sql#vulnerability#git#auth

ZUSOART ID

ZA-2023-07

CVE ID

CVE-2023-34210

Vulnerability Type

CWE-89 Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)

CVSS

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N (7.7)

Description

SQL Injection in create customer group function of EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to execute arbitrary SQL commands via the ctl00$ContentPlaceHolder1$txtCustSQL parameter.

Vendor

EasyUse Digital Technology

Product

Category

Version affected

EasyUse MailHunter Ultimate

2023 and earlier

Product Support

Contact EasyUse Digital Technology for version updates.

Release date

2023/10/17

Credit

Chia-Hao Chang (Jerry Chang) of ZUSO ART

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907