An authenticated SQL injection vulnerability exists in Advantech iView versions prior to v5.7.4 build 6752. An authenticated remote attacker can bypass checks in com.imc.iview.utils.CUtils.checkSQLInjection() to perform blind SQL injection.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://www.tenable.com/security/research/tra-2023-24 |     | 
History
                    Tue, 22 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: tenable
Published: 2023-07-31T00:00:00
Updated: 2024-10-22T15:33:26.154Z
Reserved: 2023-07-27T00:00:00
Link: CVE-2023-3983
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-02T07:08:50.874Z
 NVD
                        NVD
                    Status : Modified
Published: 2023-07-31T19:15:18.243
Modified: 2024-11-21T08:18:28.207
Link: CVE-2023-3983
 Redhat
                        Redhat
                    No data.