CVE-2023-31433

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
02/05/2023
Last modified:
30/01/2025

Description

A SQL injection issue in Logbuch in evasys before 8.2 Build 2286 and 9.x before 9.0 Build 2401 allows authenticated attackers to execute SQL statements via the welche parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:evasys:evasys:8.2:-:*:*:*:*:*:*
cpe:2.3:a:evasys:evasys:9.0:-:*:*:*:*:*:*