Vulnerability Description
SQL injection vulnerability in Knovos Discovery v.22.67.0 allows a remote attacker to execute arbitrary code via the /DiscoveryProcess/Service/Admin.svc/getGridColumnStructure component.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Knovos | Discovery | 22.67.0 |
Related Weaknesses (CWE)
References
- https://github.com/aleksey-vi/CVE-2023-47460ExploitThird Party Advisory
- https://www.knovos.comProduct
- https://github.com/aleksey-vi/CVE-2023-47460ExploitThird Party Advisory
- https://www.knovos.comProduct
FAQ
What is CVE-2023-47460?
CVE-2023-47460 is a vulnerability with a CVSS score of 8.8 (HIGH). SQL injection vulnerability in Knovos Discovery v.22.67.0 allows a remote attacker to execute arbitrary code via the /DiscoveryProcess/Service/Admin.svc/getGridColumnStructure component.
How severe is CVE-2023-47460?
CVE-2023-47460 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-47460?
Check the references section above for vendor advisories and patch information. Affected products include: Knovos Discovery.