HIGH🇵🇱 Wersja polska

CVE-2023-6903

CVSS 7.3v3.1pub. 2023-12-17upd. 2024-11-21

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. This affects an unknown part of the file /admin/singlelogin.php?submit=1. The manipulation of the argument loginId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248265 was assigned to this vulnerability.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  • Netentsec Application Security Gateway

    APP
    Netentsec
    6.3.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2023-30242CRITICAL9.8PL ✓same product

SQL injection w Netentsec NS-ASG v6.3 — komponent add_ikev2.php

CVE-2024-2647HIGH7.3same product

A vulnerability, which was classified as critical, has been found in Netentsec NS-ASG Application Security Gat...

CVE-2023-7161HIGH7.3same product

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. ...

CVE-2023-30243HIGH7.5same product

Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allow...

CVE-2024-6007MEDIUM5.3same product

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. Th...