CVE-2023-35851

Publication date

2023-09-18 02:33:59

Family

twcert

State

PUBLISHED

Description

SUNNET WMPro portals FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to obtain sensitive information via a database.