CVE-2023-39980 - CVE House
Back to Database
Status published High CVE-2023-39980

MXsecurity Authenticated Information Disclosure Due to SQL Injection

Vulnerability Description

A vulnerability that allows the unauthorized disclosure of authenticated information has been identified in MXsecurity versions prior to v1.0.1. This vulnerability arises when special elements are not neutralized correctly, allowing remote attackers to alter SQL commands.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-39980

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

MXsecurity Series
Vulnerable Versions:
1.0

Timeline

Official Publish: September 2nd, 2023
Last Modified: September 27th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

Weaknesses (CWE)