Thinking Software Technology Co., Ltd. Efence - SQL Injection
Vulnerability Description
Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-22900
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- DEVCORE
Affected Vendor
Thinking Software Technology Co., Ltd.
View all reports →