← Back to CVE List

CVE-2023-43743

Published: 2023-12-08T01:15Z
Last Modified: 2024-11-21T08:24Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an authenticated attacker to execute arbitrary SQL queries on the backend database via the filter parameter in requests to the /newapi/ endpoint in the Zultys MX web interface. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt