VulnerabilityAnalyzed
CVE-2023-42237
An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i_command.php.
LOW 3.8EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i_command.php.
- CVSS 3.1
- 3.8 LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- seling/visual access manager
- Source
- cve@mitre.org
References
- https://gitlab.com/daniele_m/cve-list/-/blob/main/README.mdThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.