Security Advisory

CVE-2023-4037

9.9
CRITICAL

Vulnerability Description

Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter.
Published Date October 4, 2023
Official Source NIST NVD Advisory