← All CVEs

CVE-2023-34133

high · 7.5

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

7.5
CVSS
72.6%
EPSS (exploit prob.)
99th
EPSS percentile
2023-07-13
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
sonicwallanalytics<= 2.5.0.4-r7
sonicwallglobal_management_system< 9.3.2
sonicwallglobal_management_system9.3.2
sonicwallglobal_management_system9.3.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-34133