CVE-2023-0953

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
01/03/2023
Last modified:
12/03/2025

Description

Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.<br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:devolutions:devolutions_server:*:*:*:*:*:*:*:* 2022.3.12 (including)