{ "id": "CVE-2023-26813", "sourceIdentifier": "cve@mitre.org", "published": "2023-04-28T20:15:13.970", "lastModified": "2023-04-28T20:15:13.970", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "SQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java in wangmarket CMS 4.10 allows remote attackers to run arbitrary SQL commands via the TableName parameter to /plugin/dataDictionary/tableView.do." } ], "metrics": {}, "references": [ { "url": "https://github.com/xnx3/wangmarket/issues/7", "source": "cve@mitre.org" } ] }