Vulnerabilities > Dokmee

DATE CVE VULNERABILITY TITLE RISK
2023-12-14 CVE-2023-47261 Unspecified vulnerability in Dokmee Enterprise Content Management 7.4.6
Dokmee ECM 7.4.6 allows remote code execution because the response to a GettingStarted/SaveSQLConnectionAsync /#/gettingstarted request contains a connection string for privileged SQL Server database access, and xp_cmdshell can be enabled.
network
low complexity
dokmee
critical
9.8