← back
CVE-2023-32115

SQL Injection in Master Data Synchronization (MDS COMPARE TOOL)

CVSS 4.2 MEDIUMEPSS 0.2%CWE-89
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.2EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
13 Jun 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An attacker can exploit MDS COMPARE TOOL and use specially crafted inputs to read and modify database commands, resulting in the retrieval of additional information persisted by the system.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →