CVE-2023-24835

HIGH

Softnext SPAM SQR < 2.221231 - Authenticated Code Injection

Title source: llm
STIX 2.1

Description

Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function. An authenticated remote attacker with administrator privilege can exploit this vulnerability to execute arbitrary system command to perform arbitrary system operation or disrupt service.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0093
EPSS Percentile 56.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
softnext/spam_sqr < 2.221231
Published Mar 27, 2023
Tracked Since Feb 18, 2026