Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-4309

Опубликовано: 10 окт. 2023
Источник: nvd
CVSS3: 10
CVSS3: 9.8
EPSS Низкий

Описание

Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:electionservicesco:internet_election_service:-:*:*:*:*:*:*:*

EPSS

Процентиль: 68%
0.00558
Низкий

10 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-89
CWE-89

Связанные уязвимости

CVSS3: 10
github
больше 2 лет назад

Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12.

EPSS

Процентиль: 68%
0.00558
Низкий

10 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-89
CWE-89