Vulnerabilities > CVE-2023-47261 - Unspecified vulnerability in Dokmee Enterprise Content Management 7.4.6
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Dokmee ECM 7.4.6 allows remote code execution because the response to a GettingStarted/SaveSQLConnectionAsync /#/gettingstarted request contains a connection string for privileged SQL Server database access, and xp_cmdshell can be enabled.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |