Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.
                
            References
                    | Link | Resource | 
|---|---|
| https://devolutions.net/security/advisories/DEVO-2023-0003 | Vendor Advisory | 
Configurations
                    History
                    No history.
Information
                Published : 2023-03-01 08:15
Updated : 2023-11-07 04:02
NVD link : CVE-2023-0953
Mitre link : CVE-2023-0953
CVE.ORG link : CVE-2023-0953
JSON object : View
Products Affected
                devolutions
- devolutions_server
 
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
