2023-12-14 19:00:28 +00:00

24 lines
762 B
JSON

{
"id": "CVE-2023-47261",
"sourceIdentifier": "cve@mitre.org",
"published": "2023-12-14T17:15:07.933",
"lastModified": "2023-12-14T17:17:50.580",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "Dokmee ECM 7.4.6 allows remote code execution because the response to a GettingStarted/SaveSQLConnectionAsync /#/gettingstarted request contains a connection string for privileged SQL Server database access, and xp_cmdshell can be enabled."
}
],
"metrics": {},
"references": [
{
"url": "https://h3x0s3.github.io/CVE2023~47261/",
"source": "cve@mitre.org"
},
{
"url": "https://www.dokmee.com/Support-Learn/Updates-Change-Log",
"source": "cve@mitre.org"
}
]
}