A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read database data via SQL commands injected in the search parameter.
References
Link Resource
https://www.cvcn.gov.it/cvcn/cve/CVE-2023-36652 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-12T00:00:00

Updated: 2023-12-12T00:35:53.203459

Reserved: 2023-06-25T00:00:00


Link: CVE-2023-36652

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-12T01:15:10.270

Modified: 2023-12-13T20:42:54.737


Link: CVE-2023-36652

JSON object: View

cve-icon Redhat Information

No data.

CWE