Vulnerabilities > CVE-2023-22900 - Unspecified vulnerability in Thinkingsoftware Efence 1.2.58
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |