RoadFlow Visual Process Engine .NET Core Mvc Login sql injection
Published Jun 12, 2023
8.8
HIGHCVSS 3.1
EPSS 0.73%
Description
A vulnerability, which was classified as critical, has been found in RoadFlow Visual Process Engine .NET Core Mvc 2.13.3. Affected by this issue is some unknown functionality of the file /Log/Query?appid=0B736354-9473-4D66-B9C0-15CAC149EB05&tabid=tab_0B73635494734D66B9C015CAC149EB05 of the component Login. The manipulation of the argument sidx/sord leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-231230 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 2.13.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| RoadFlow | Visual Process Engine .NET Core Mvc | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-43886 Advisory
- https://github.com/yangxixx/vulhub/blob/master/activemq/RoadFlow.md exploitThird Party Advisory
- https://vuldb.com/?ctiid.231230 signaturepermissions-requiredThird Party Advisory
- https://vuldb.com/?id.231230 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-43886 | Advisory | |
| https://github.com/yangxixx/vulhub/blob/master/activemq/RoadFlow.md | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.231230 | signaturepermissions-requiredThird Party Advisory | |
| https://vuldb.com/?id.231230 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.