PoC Index

CVE-2023-34133

HIGH 7.5EPSS 72.6%

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
72.58% chance of exploitation in the next 30 days, 99th percentile
Nuclei
high · CWE-89
Published
2023-07-13
Updated
2025-04-23

Nuclei templates (1)

Metasploit modules (1)

References

Related