A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the select parameter in models/base_client.py component.
References
Link | Resource |
---|---|
https://github.com/luvsn/OdZoo/tree/main/exploits/pdm/2 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
19 Sep 2023, 19:19
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/luvsn/OdZoo/tree/main/exploits/pdm/2 - Exploit, Third Party Advisory | |
First Time |
Didotech engineering \& Lifecycle Management
Didotech |
|
CWE | CWE-89 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CPE | cpe:2.3:a:didotech:engineering_\&_lifecycle_management:*:*:*:*:*:*:*:* |
15 Sep 2023, 00:31
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-15 00:15
Updated : 2024-02-28 20:33
NVD link : CVE-2023-40955
Mitre link : CVE-2023-40955
CVE.ORG link : CVE-2023-40955
JSON object : View
Products Affected
didotech
- engineering_\&_lifecycle_management
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')