← Back to CVE List

CVE-2023-26813

Published: 2023-04-28T20:15Z
Last Modified: 2025-01-31T17:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
SQL injection vulnerability in com.xnx3.wangmarket.plugin.dataDictionary.controller.DataDictionaryPluginController.java in wangmarket CMS 4.10 allows remote attackers to run arbitrary SQL commands via the TableName parameter to /plugin/dataDictionary/tableView.do. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt