CVE-2023-39593
MEDIUM 5.6EPSS 0.7%
Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
- CVSS v3.1
- 5.6 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L - EPSS
- 0.73% chance of exploitation in the next 30 days, 52th percentile
- Published
- 2024-10-17
- Updated
- 2024-10-20
Proof-of-concept exploits (1)
- Ant1sec-ops/CVE-2023-395932★ · 2024-10-18