CVE-2023-37196
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command
('SQL Injection') vulnerabili
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the alert settings of endpoints on DCE.
HIGH · CVSS 8.8
EPSS 0.00416
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0