CVE-2023-3983
HIGH 8.8EPSS 16.7%
An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 16.71% chance of exploitation in the next 30 days, 97th percentile
- Published
- 2023-07-31
- Updated
- 2024-10-22