Vulnerability Description
SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php?controller=admin_commonuser parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tosec | Kirin Fortress Machine | 1.7-2020-0610 |
Related Weaknesses (CWE)
References
- https://gist.github.com/yinfei6/b13e7527887ac0eb809fa0b6f36305e1Third Party Advisory
- https://www.tosec.com.cnProduct
- https://gist.github.com/yinfei6/b13e7527887ac0eb809fa0b6f36305e1Third Party Advisory
- https://www.tosec.com.cnProduct
FAQ
What is CVE-2023-26784?
CVE-2023-26784 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL Injection vulnerability found in Kirin Fortress Machine v.1.7-2020-0610 allows attackers to execute arbitrary code via the /admin.php?controller=admin_commonuser parameter.
How severe is CVE-2023-26784?
CVE-2023-26784 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-26784?
Check the references section above for vendor advisories and patch information. Affected products include: Tosec Kirin Fortress Machine.