CVE-2023-23634 Information

Description

SQL Injection vulnerability in Documize version 5.4.2 allows remote attackers to execute arbitrary code via the user parameter of the /api/dashboard/activity endpoint.

Reference

https://herolab.usd.de/en/security-advisories/usd-2022-0066/

Share on: