CVE-2023-28701

ELITE TECHNOLOGY CORP. Web Fax has a vulnerability of SQL Injection. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to perform arbitrary system commands, disrupt service or terminate service.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-7145-1a0d4-1.html Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:elite:webfax:-:*:*:*:*:*:*:*

History

09 Jun 2023, 16:34

Type Values Removed Values Added
First Time Elite
Elite webfax
CPE cpe:2.3:a:elite:webfax:-:*:*:*:*:*:*:*
References (MISC) https://www.twcert.org.tw/tw/cp-132-7145-1a0d4-1.html - (MISC) https://www.twcert.org.tw/tw/cp-132-7145-1a0d4-1.html - Third Party Advisory

02 Jun 2023, 12:48

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-02 11:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-28701

Mitre link : CVE-2023-28701

CVE.ORG link : CVE-2023-28701


JSON object : View

Products Affected

elite

  • webfax
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')