Vulnerability Description
Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qualitor | Qualitor | <= 8.20 |
Related Weaknesses (CWE)
References
- https://openxp.xpsec.co/blog/cve-2023-47253ExploitThird Party Advisory
- https://www.linkedin.com/in/hairrison-wenning-4631a4124/Not Applicable
- https://www.linkedin.com/in/xvinicius/Permissions Required
- https://www.qualitor.com.br/official-security-advisory-cve-2023-47253Vendor Advisory
- https://www.qualitor.com.br/qualitor-8-20ProductRelease Notes
- https://openxp.xpsec.co/blog/cve-2023-47253ExploitThird Party Advisory
- https://www.linkedin.com/in/hairrison-wenning-4631a4124/Not Applicable
- https://www.linkedin.com/in/xvinicius/Permissions Required
- https://www.qualitor.com.br/qualitor-8-20ProductRelease Notes
FAQ
What is CVE-2023-47253?
CVE-2023-47253 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/request/processVariavel.php gridValoresPopHidden parameter.
How severe is CVE-2023-47253?
CVE-2023-47253 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-47253?
Check the references section above for vendor advisories and patch information. Affected products include: Qualitor Qualitor.