TAPHOME SQL Injection in Core Platform
Vulnerability Description
An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary SQL directives into an SQL query and execute arbitrary SQL commands and get full reading access. This may also lead to limited write access and temporary Denial-of-Service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-2760
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Noam Moshe of Claroty Research
Affected Vendor
TAPHOME
View all reports →