Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-3864


Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.


Published

2023-08-11T12:15:09.293

Last Modified

2024-11-21T08:18:15.003

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-89
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application snowsoftware snow_license_manager ≤ 9.30.1 Yes
Operating System microsoft windows - No

References