CVE-2023-1863
SQLi in Eskom Computer Water Metering Software
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
14 Apr 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection.
This issue affects Water Metering Software: before 23.04.06.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Eskom · Water Metering SoftwareWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →